This is our old Q&A Site. Please post any new questions and answers at


(As translated by Google): I'm sorry, my English is not very good, and we can only write Chinese. Use wireshark process, I encountered a problem, is that I would like to set up filters in Ethereal before, only to grab the HTTP protocol packet, why when I set the NIC to input HTTP is shown by the color filter conditions this means that the settings wrong, but can enter the TCP like. I would like to ask what reason?

asked 17 Dec '12, 17:59

jun's gravatar image

accept rate: 0%

closed 20 Dec '12, 23:24

Kurt%20Knochner's gravatar image

Kurt Knochner ♦

Sounds like a display filter versus capture filter question.

(17 Dec '12, 23:53) Jaap ♦

The question has been closed for the following reason "Duplicate Question of" by Kurt Knochner 20 Dec '12, 23:24

您可以不使用 HTTP作为捕捉过滤器,因为这不是一个有效的libpcap的过滤器语法。而 TCP是一个有效的过滤器。



此致 库尔特

You cannot use http as a capture filter, as that is not a valid libpcap filter syntax. whereas tcp is a valid filter.

See here:

Please use this filter instead: tcp port 80


permanent link

answered 18 Dec '12, 12:15

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
accept rate: 15%

如果使用tcp port 80这个过滤语法的话,那么他只能抓取经过80端口的HTTP协议哦,如果有些HTTP协调不是通过80端口的又要怎么抓呢?

(18 Dec '12, 17:16) jun

这个要用 高级过滤器才行

抓Http GET 或者 HEAD (80 可以改为任意) tshark 'tcp port 80 and (((ip[2:2] - ((ip[0]&0xf)<<2)) - ((tcp[12]&0xf0)>>2)) != 0)' -R 'http.request.method == "GET" || http.request.method == "HEAD"

PS:LZ 怎么跑这里来问了 ?

permanent link

answered 18 Dec '12, 21:35

Missuniverse110's gravatar image

accept rate: 0%

那个高级过滤器要另外安装吗? 不在问在那里问,还有中文版的论坛吗?

(18 Dec '12, 23:49) jun



Can you please repeat the question about installing the filter?

There is no chinese version of this site. I suggest to ask in english (ask a colleague of yours), as Google translate adds some errors, which makes communication somewhat hard.

(19 Dec '12, 00:27) Kurt Knochner ♦

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 17 Dec '12, 17:59

question was seen: 6,094 times

last updated: 20 Dec '12, 23:24

p​o​w​e​r​e​d by O​S​Q​A