githubEdit

Display Filter Example

  • ip.src == $ipaddress: filter packet from source ip address

  • ip.dst == $ipaddress: filter packet to destination ip address

  • ip.src==$ipaddress and ip.dst==$ipaddress: filter packets between source and destination ip address

  • dns: all dns packets

  • dns.qry.type==1: dns query a record

  • dns.qry.type==2: dns query ns record

  • (dns.qry.name contains keyword) && (dns.qry.type==1): dns ns query contains keywords

  • dns.qry.name==$domainname: filter dns packet that queries $domainname

  • dns.qry.name contains $domainname: filter dns packet that involves $domainname

  • dns.resp.name==$domainname: filter dns response packet for $domainname

  • dns.resp.name contains $domainname: filter dns response packet matching $domainname

  • dns.flags.response==0: filter dns query only

  • dns.flags.response==1: filter dns response only

Last updated