Hi, I am trying to use the eth.addr filter, i need to see only the comunication from and to this mac address i use the filter eth.addr==2c:39:96:54:89:48 but blank page... i have 2c:39:96:54:89:48 traffic, when i use sll.src.eth == 2c:39:96:54:89:48 i have a lot of packet.
I am using the version 1.10.3 of wireshark.
asked 27 Nov '13, 00:47
edited 27 Nov '13, 06:14
You apparently have a Linux cooked-mode capture file. You can verify this in Wireshark by viewing the encapsulation entry in the
For further information on this topic, refer to the Linux cooked-mode capture wiki page.
answered 27 Nov '13, 06:13