This is our old Q&A Site. Please post any new questions and answers at

I am working with wireshark(tshark). I want to capture specific protocol like ipv6, coap13 etc. i added coap13.lua file.

alt text

i tried to capture ipv6 with "tshark.exe" -i 3 -f "ip6" -a duration:400 -a filesize:20480 -a files:512 -w "C:\Packet_Capture.pcap"

it runs well

but when i want to capture CoAP or CoAP13 with

"tshark.exe" -i 3 -f "coap13" -a duration:400 -a filesize:20480 -a files:512 -w "C:\Packet_Capture.pcap"

it didn't work.

alt text

What is the syntax to capture CoAP protocol? Where can i find the list(syntax) for capture filter?

asked 04 Mar '14, 02:54

Amrit's gravatar image

accept rate: 0%

edited 04 Mar '14, 02:54

As per the error message, display filters and capture filters are different. Also as per the error message, the Users Guide has informative sections on display and capture filters with links to other topics of interest.

In your particular case there is no explicit capture filter syntax for the protocols CoAP or CoAP13, but you could use udp port 5683 if the CoAP traffic is on the registered port.

permanent link

answered 04 Mar '14, 03:14

grahamb's gravatar image

grahamb ♦
accept rate: 22%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 04 Mar '14, 02:54

question was seen: 2,997 times

last updated: 04 Mar '14, 03:14

p​o​w​e​r​e​d by O​S​Q​A