Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] tzsp capture filter ?

Date Prev · Date Next · Thread Prev · Thread Next
From: Pascal Quantin <pascal.quantin@xxxxxxxxx>
Date: Fri, 25 Sep 2015 10:37:45 +0200
2015-09-25 9:25 GMT+02:00 Kai Hendry <kai.hendry@xxxxxxxxx>:
Hi there,

tzsp as a display filter works just fine, but how to do use it as a
capture filter?
http://s.natalian.org/2015-09-25/1443165826_546x1043.png

https://www.youtube.com/watch?v=zj2vLZOVOT0


I have a very annoying UX whereby, I follow the TCP stream (wish there
was a shortcut) and then clear the _expression_ to then have to put
"tzsp" back.

Kind regards,

Hi Kay,

assuming your TZSP traffic is generated on the default UDP port 37008, you could use the following capture filter:
udp port 37008

Please see https://wiki.wireshark.org/CaptureFilters for more details.

Best regards,
Pascal.