Open In App

Display Filter Expression Dialog Box in Wireshark

Display filters search and change the display of only those packets that match with the given filter primitive. When we use a Display filter after running a packet capture it’ll just display whatever we typed in the Display Filter dialogue box else part is simply omitted until we clear the filter text box and then everything appears back. 

When we get familiar with Wireshark’s filter primitive and know what labels we use in our filters it becomes easy to type a filter string. But if we are unfamiliar and new to Wireshark then it becomes very confusing to try to figure out what to type. The “Display Filter Expression” dialogue box helps us to learn how to write Wireshark’s display filter primitive.



Note: When we get the syntax right then we will see that the background turns green. Now if we type something wrong then the background turns to be red. That tells us that Wireshark does not recognize that as an appropriate display filter syntax. 

Wireshark Display Filter Expression Dialog Box : 

To open Wireshark’s Display Filter Expression Dialog Box follow the below steps : 



 

This will open up the Display Filter Expression dialogue box.

 

The following are the fields available in the Display Filter Expression dialogue box.

Article Tags :