This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

dumpcap -i 1 -f "ip.addr == 192.168.11.61" -b files:500 -b filesize:30000 -w textcap.pcap, error is string is not a valid capture filter. What is wrong with the string?

asked 22 Nov '10, 13:16

qs_tech_support's gravatar image

qs_tech_support
1111
accept rate: 0%


What's wrong is that it's a display filter, not a capture filter; capture filters are implemented by libpcap/WinPcap, and have a different syntax from display filters. (Display filters require a full-blown Wireshark packet dissection; dumpcap does not include Wireshark dissectors, because it might have to run with special privileges, and the Wireshark dissection code is a lot of code to run with privileges.)

The equivalent capture filter would be "host 192.168.11.61"; it would also work as a capture filter in Wireshark, TShark, and tcpdump.

permanent link

answered 22 Nov '10, 13:40

Guy%20Harris's gravatar image

Guy Harris ♦♦
17.4k335196
accept rate: 19%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×89

question asked: 22 Nov '10, 13:16

question was seen: 7,078 times

last updated: 22 Nov '10, 13:40

p​o​w​e​r​e​d by O​S​Q​A