Hi, I am trying to use the eth.addr filter, i need to see only the comunication from and to this mac address i use the filter eth.addr==2c:39:96:54:89:48 but blank page... i have 2c:39:96:54:89:48 traffic, when i use sll.src.eth == 2c:39:96:54:89:48 i have a lot of packet. I am using the version 1.10.3 of wireshark. asked 27 Nov '13, 00:47 Pouet-Lord edited 27 Nov '13, 06:14 cmaynard ♦♦ |
One Answer:
You apparently have a Linux cooked-mode capture file. You can verify this in Wireshark by viewing the encapsulation entry in the For further information on this topic, refer to the Linux cooked-mode capture wiki page. answered 27 Nov '13, 06:13 cmaynard ♦♦ |
Hello, thank you for your reply.