This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

We are doing an audit on a SPAN port to verify source ip traffic to destination for a week . Is there a way to only record 1 instance of ip hosts (source to destination) and then ignore any continuos communications between the 2 ? We realy dont need any more data and need to leave wireshark on for about a week.

Thank you

asked 17 Jul '15, 05:15

mtrujillano's gravatar image

mtrujillano
6112
accept rate: 0%


No, Wireshark does not support adaptive filtering based on what it has seen in packets. You may want to look at Netflow statistics gathering which seems to be more like what you're looking for.

permanent link

answered 17 Jul '15, 05:19

Jasper's gravatar image

Jasper ♦♦
23.8k551284
accept rate: 18%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×178
×40
×30
×17

question asked: 17 Jul '15, 05:15

question was seen: 1,290 times

last updated: 17 Jul '15, 05:19

p​o​w​e​r​e​d by O​S​Q​A