Configuring display filters
In order to configure display filters, you can choose one of the several options:
- Choosing from the filters menus
- Writing the syntax directly into the display filter window (while working with Wireshark; after a while this will become your favorite)
- Choosing a parameter in the packet pane and defining it as a filter
wiresharkwith command line ; this will be discussed in Appendix
This chapter discusses the first three options.
In general, a display filter string takes the form of a series of primitive expressions connected by conjunctions (and, or, or something else) and optionally preceded by
[not] Expression [and|or] [not] Expression...
Expression can be any filter expression, such ...