This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

When I look in my capture, I see several:

SMB2 Create Request File: filename.txt SMB2 Create Response, Error: STATUS_OBJECT_NAME_NOT_FOUND

How can I write a query where the word "Create" is present in the Info field? I can do an ip.addr == 192.168.80.10, but I only want to see the create requests or errors, and nothing else.

asked 08 Jul '15, 06:36

kspinnato's gravatar image

kspinnato
11113
accept rate: 0%


smb2.cmd == 5

For your complete filter: smb2.cmd == 5 && ip.addr==192.168.80.10

permanent link

answered 08 Jul '15, 08:59

Amato_C's gravatar image

Amato_C
1.1k142032
accept rate: 14%

That works perfect! Thanks for helping me out with this filter.

(08 Jul '15, 09:13) kspinnato
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×1,620
×184
×12

question asked: 08 Jul '15, 06:36

question was seen: 1,272 times

last updated: 08 Jul '15, 09:13

p​o​w​e​r​e​d by O​S​Q​A