<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://beardedmaker.com/wiki/index.php?action=history&amp;feed=atom&amp;title=Wireshark</id>
		<title>Wireshark - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://beardedmaker.com/wiki/index.php?action=history&amp;feed=atom&amp;title=Wireshark"/>
		<link rel="alternate" type="text/html" href="https://beardedmaker.com/wiki/index.php?title=Wireshark&amp;action=history"/>
		<updated>2026-04-26T23:03:53Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.4</generator>

	<entry>
		<id>https://beardedmaker.com/wiki/index.php?title=Wireshark&amp;diff=2524&amp;oldid=prev</id>
		<title>Beard at 18:15, 7 June 2018</title>
		<link rel="alternate" type="text/html" href="https://beardedmaker.com/wiki/index.php?title=Wireshark&amp;diff=2524&amp;oldid=prev"/>
				<updated>2018-06-07T18:15:36Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&lt;br /&gt;
FILTER SYNTAX:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
eq, ==    Equal&lt;br /&gt;
ne, !=    Not Equal&lt;br /&gt;
gt, &amp;gt;     Greater Than&lt;br /&gt;
lt, &amp;lt;     Less Than&lt;br /&gt;
ge, &amp;gt;=    Greater than or Equal to&lt;br /&gt;
le, &amp;lt;=    Less than or Equal to&lt;br /&gt;
&lt;br /&gt;
eq, ==    Equal&lt;br /&gt;
ne, !=    Not Equal&lt;br /&gt;
gt, &amp;gt;     Greater Than&lt;br /&gt;
lt, &amp;lt;     Less Than&lt;br /&gt;
ge, &amp;gt;=    Greater than or Equal to&lt;br /&gt;
le, &amp;lt;=    Less than or Equal to&lt;br /&gt;
&lt;br /&gt;
contains&lt;br /&gt;
matches&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
EXAMPLES:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
tcp&lt;br /&gt;
tcp or udp&lt;br /&gt;
not arp&lt;br /&gt;
!arp&lt;br /&gt;
!(arp or dns or stp)&lt;br /&gt;
tcp.port == 53&lt;br /&gt;
tcp.port in {80 443 8080}&lt;br /&gt;
ip.addr == 1.1.1.1&lt;br /&gt;
!(ip.addr == 1.1.1.1) - do this instead of &amp;quot;ip.addr != 1.1.1.1&amp;quot;&lt;br /&gt;
ip.src == 1.1.1.1&lt;br /&gt;
ip.dst == 1.1.1.1/24&lt;br /&gt;
eth.addr == 00:00:00:00:00:00&lt;br /&gt;
eth.src == 00:00:00:00:00:00&lt;br /&gt;
eth.dst == 00:00:00:00:00:00&lt;br /&gt;
ipv6.addr == ::1&lt;br /&gt;
&lt;br /&gt;
http.request.method == &amp;quot;POST&amp;quot;&lt;br /&gt;
smb.path contains &amp;quot;\\\\SERVER\\SHARE&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
SLICE:&lt;br /&gt;
&lt;br /&gt;
The following syntax governs slices:&lt;br /&gt;
    [i:j]    i = start_offset, j = length&lt;br /&gt;
    [i-j]    i = start_offset, j = end_offset, inclusive.&lt;br /&gt;
    [i]      i = start_offset, length = 1&lt;br /&gt;
    [:j]     start_offset = 0, length = j&lt;br /&gt;
    [i:]     start_offset = i, end_offset = end_of_field&lt;br /&gt;
	&lt;br /&gt;
example:&lt;br /&gt;
eth.addr[0:3] == 00:00:00 - match first 3 bytes (start on byte 0, count 3 bytes)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
PREFERENCES:&lt;br /&gt;
&lt;br /&gt;
Appearance &amp;gt; Columns &amp;gt; + &amp;gt; Add a custom type and put &amp;quot;tcp.port&amp;quot; under Fields.&lt;br /&gt;
Appearance &amp;gt; [uncheck] &amp;quot;Confirm unsaved capture files&amp;quot;&lt;br /&gt;
Appearance &amp;gt; Main toolbar style = Icons &amp;amp; Text&lt;br /&gt;
Protocols &amp;gt; [check] Display hidden protocol items&lt;/div&gt;</summary>
		<author><name>Beard</name></author>	</entry>

	</feed>