Chapter 3. Using Display Filters

In this chapter you will learn the following:

  • Configuring display filters
  • Configuring Ethernet, ARP, host, and network filters
  • Configuring TCP/UDP filters
  • Configuring specific protocol filters
  • Configuring substring operator filters
  • Configuring macros

Introduction

In this chapter we will learn how to work with display filters. Display filters are filters that we apply after capturing data (filtered by capture filters or not), and when we wish to display only part of the data.

Display filters can be implemented in order to locate various types of data:

  • Parameters such as the IP address, TCP or UDP port numbers, URLs, and server names
  • Conditions such as "packet length shorter than..." and the TCP port range
  • Phenomena such as TCP retransmissions, duplicate and other types of ACKs, various protocol error codes, and flag existence
  • Various applications parameters such as Short Message Service (SMS) source and destination numbers and Server Message Block (SMB) server names

Any data that is sent over the network can be filtered, and when filtered, you can create statistics and graphs according to it.

As we will describe in the recipes in this chapter, there are various ways to configure display filters: from predefined menus, from the packet pane, or by writing the syntax directly.

Tip

While using display filters, don't forget that all the data was already captured and the display filters only decide what to display. Therefore, after filtering data, the capture file still contains the original data that was captured. You may later save the complete data or only the displayed data.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.142.97.235