Filtering rules commonly used in wireshark
1. Find the destination address and source address "
Ip.src = = 10.1086.90 and ip.dst eq 115.29.47.145
two。 Filter port
If tcp.port = = 80, the packets with source port and destination port 80 are filtered out.
If tcp.srcport = 80, only packets with source port 80 are filtered.
3. Protocol filtering
Enter the protocol name directly in the filter box. For example, if you filter the HTTP protocol, http
4.http mode filtering
Filter get packets: http.request.method = = "GET"
Filter post packets: http.request.method = = "POST"
5. Connector and
Use and connections when filtering multiple conditions
Ip.src = = 10.10.86.90 and http