I know that for some protocols, such as http, you can just type "http" in the filter box and wireshark will filter it. However, this doesn't seem to work for many protocols, including MDNS, which is what I'm trying to filter on right now. Is there a way to filter on what is ACTUALLY displayed in the PROTOCOL column of the list? asked 02 Aug '13, 07:22 ev1lr0b0t |
One Answer:
You can only search for those 'fields' that are registered by a dissector. As the DNS dissector (which also handles MDNS), does not register a field "MDNS", you can't search for it.
No, that's currently not possible, as there is no way to do a text search in the columns itself. A possible solution for your problem is this display filter.
which is a simple definition for MDNS. You can also include the multicast IP
Regards answered 08 Aug '13, 02:28 Kurt Knochner ♦ |