Wireshark Display Filters

Image by StockSnap from Pixabay

This is a list of Wireless display filters for various functions. I am adding to it all the time.

Table of Contents

Operators

OperationOperator
AND&&
OR||
NOT!
Equals==
Not Equals!=
Greater Than>
Less Than<
Less Than or Equal<=
Greater Than or Equal>=
Containscontains

MAC Address (Layer 2)

DescriptionFilter
Source MAC Addresseth.src == 00:00:00:00:00:00
Destination MAC Addresseth.dst == 00:00:00:00:00:00
Source or DestinationΒ  MAC Addresseth.addr == 00:00:00:00:00:00

IP Address (Layer 3)

DescriptionFilter
Source IP Addressip.src == 192.168.0.1
Destination IP Addressip.dst == 192.168.0.1
Source or Destination IP Addressip.addr == 192.168.0.1

Port

DescriptionFilter
UDP Source Portudp.srcport == 53
TCP Source Porttcp.srcport == 53
UDP Destination Portudp.dstport == 53
TCP Destination Porttcp.dstport == 53
UDP Source or Destination Portudp.port == 53
TCP Source or Destination Porttcp.port == 53

Protocols

Filter for most standards and protocols just with the name, for example:

  • arp
  • dns
  • dhcp
  • http
  • https
  • lldp
  • stp
  • ip
  • eth
  • sip
  • smb

Wireshark supports thousands of standard names.

DNS

DescriptionFilter
Querydns.qry.name contains google

QoS

DescriptionFilter
DSCP Expeditated Forwardingip.dsfield.dscp == 46
DSCP Assured Forwardingip.dsfield.dscp == 34
DSCP CS3ip.dsfield.dscp == 24
DSCP Best Effortip.dsfield.dscp == 0
DSCP Scavengerip.dsfield.dscp == 8

Text Search

DescriptionFilter
Text Searchframe contains "password"