This is our old Q&A Site. Please post any new questions and answers at

I am trying to do a regex in wireshark on the following http header and want to filter the ones with an empty value.


in the trace it shows User-Agent: \r\n

I tried a regex like the following to match User-Agent: followed by a space, then end of line.

frame matches "User-Agent:[\s]$"

but it doesnt work.

Can someone advise whats wrong? thanks

asked 26 Jun '13, 15:28

brumik's gravatar image

accept rate: 0%

I believe the "$" will anchor the regex to the end of the whole frame, not one particular line in the frame. Could you try:

frame matches "\\r\\nUser-Agent: \\r\\n"
permanent link

answered 27 Jun '13, 09:20

SYN-bit's gravatar image

SYN-bit ♦♦
accept rate: 20%

edited 27 Jun '13, 15:11

I assume you meant "matches" ? but yes it did work without the $ Also without the \r\n at the start. Thanks everyone for the help.

(27 Jun '13, 13:49) brumik

Yes I did, it's corrected :-)

Glad the filter works for you!

(27 Jun '13, 15:12) SYN-bit ♦♦

If a response answers your question, please mark it as the accepted answer for the benefit of others. Refer to the FAQ for more information.

(27 Jun '13, 20:02) cmaynard ♦♦

Please try this:

frame matches "User-Agent: \\r\\n$"


permanent link

answered 26 Jun '13, 16:35

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
accept rate: 15%


frame matches "User-Agent: \r\n$"

it still didnt match though.


http.user_agent == "" matches it but I wanted to use a regex.

(27 Jun '13, 00:25) brumik

Correction I meant:

frame matches "User-Agent: \r\n$"

still didnt do the trick

(27 Jun '13, 00:27) brumik


Your "answers" have been converted to comments as that's how this site works. Please read the FAQ for more information.

(27 Jun '13, 02:27) grahamb ♦

did you try 'double backslash'? Only that works in my test capture file.

frame matches "User-Agent: \\r\\n$"

instead of

frame matches "User-Agent: \r\n$"

(27 Jun '13, 05:50) Kurt Knochner ♦

Yes I did, strangely enough it didn't match with double backslash either.

(27 Jun '13, 08:53) brumik

it does for me. What is your Wireshark version?

(27 Jun '13, 13:16) Kurt Knochner ♦
showing 5 of 6 show 1 more comments
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 26 Jun '13, 15:28

question was seen: 20,757 times

last updated: 27 Jun '13, 20:02

p​o​w​e​r​e​d by O​S​Q​A