Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] Default filter

Date Prev · Date Next · Thread Prev · Thread Next
From: Jeff Morriss <jeff.morriss.ws@xxxxxxxxx>
Date: Sun, 26 Jun 2016 22:25:17 -0400


On Fri, Jun 24, 2016 at 5:28 PM, Rudy Zijlstra <rudy@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
Hi

I am usually using wireshark remotely. This means that it will set a default filter to prevent sniffing the remote traffic it generates itself.

For me, this is not needed, as i always set filters to limit the traffic to what i need to see. If the default filter would be set only at startup, it would not be a problem, but what makes it rather irritating is that each time i want to modify the filter, it removes the filter i had set and replaces it with the default filter.

How can i disable this behavior? This is on wireshark 1.12.1

I don't think you can disable it.  It sounds like you're running into a longstanding bug report:

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9115

You might want to add yourself to the Cc: list for that bug so you'll be notified whenever any progress is made on it.