This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi, I am trying to use the eth.addr filter, i need to see only the comunication from and to this mac address i use the filter eth.addr==2c:39:96:54:89:48 but blank page... i have 2c:39:96:54:89:48 traffic, when i use sll.src.eth == 2c:39:96:54:89:48 i have a lot of packet.

I am using the version 1.10.3 of wireshark.

asked 27 Nov '13, 00:47

Pouet-Lord's gravatar image

Pouet-Lord
16114
accept rate: 0%

edited 27 Nov '13, 06:14

cmaynard's gravatar image

cmaynard ♦♦
9.3k1038142


You apparently have a Linux cooked-mode capture file. You can verify this in Wireshark by viewing the encapsulation entry in the Statistics -> Summary window. This means that there is no Ethernet encapsulation, thus the eth.addr (or any other eth filter) won't match any packets. As you've discovered, you'll need to use the sll filters.

For further information on this topic, refer to the Linux cooked-mode capture wiki page.

permanent link

answered 27 Nov '13, 06:13

cmaynard's gravatar image

cmaynard ♦♦
9.3k1038142
accept rate: 20%

Hello, thank you for your reply.

(28 Nov '13, 00:03) Pouet-Lord
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×165
×87
×7
×5
×2

question asked: 27 Nov '13, 00:47

question was seen: 9,326 times

last updated: 28 Nov '13, 02:14

p​o​w​e​r​e​d by O​S​Q​A