Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] Wireshark Capture Filter Using Offset

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Mon, 19 Jul 2010 23:25:28 -0700
On Jul 19, 2010, at 9:32 PM, j.snelders wrote:

> I think  the capture filter should be (but can't test it right now):
> dns[2:2]==0x2800

libpcap doesn't know about DNS, so that doesn't work.