Using bookmarks

On the right-hand side of the display filter, is a blue toolbar icon called bookmarks, where Wireshark's built-in filters and any saved filters reside. Other choices when working with the bookmark include Manage Display Filters and Manage Filter Expressions.

Below the save and manage selections, you will see a list of filters. Even if you have never saved a filter, you will see the list, as Wireshark has several pre-loaded filters that you can use, as shown here:

Display filter bookmark drop-down

After you create a filter, you can save the filter to the bookmark by dropping down the bookmark icon and selecting Save this filter

Once you create your own filter or select one from the drop-down list, you can press Enter or click the blue arrow on the right-hand side of the display filter to run the filter. 

On the far-right side of the display filter is an arrow that, when selected, is a drop-down menu where you can see previously used filters, also shown in the following screenshot:

Previously used display filters

A display filter can be applied before, during, or after packet capture. When you are ready to clear the filter, select the X on the right-hand side of the filter, as shown in the screenshot named Syntax checker with a yellow background.

Wireshark's display filters can easily be modified. The following section illustrates how you can edit the display filters to customize your workflow.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.16.83.150