How do I filter captured packets?

A. Once you have captured data it is possible to apply a filter to view only certain type of packets:

  1. Once you have displayed your captured data select Filter from the Display menu
  2. You can select the protocol to monitor by selecting the Protocol==Any line and click Edit - Operator
  3. A new dialog will be displayed with 3 tabs, Address, Protocol and Property. You can click Disable All to disable the protocols and then selectively add the one you require, e.g. DNS
    Click here to view image
  4. From the Property tab you can select certain matches for each protocol to refine even further.
  5. Click OK to close the dialog
  6. Click OK to the main filter dialog

The data displayed will now be that which matches the specified criteria. Do disable the filter just select "Disable Filter" from the Filter menu.

TAGS: Security
Hide comments


  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.