I'm looking for the syntax to do a capture filter on WireShark, by capturing the traffic on several (specific) IP addresses. I understand how to capture a range, and an individual IP address. However, the application I am capturing on is spread of a 'bucket' of IP addresses/servers, of which other applications are based within the same range. See my example:

ECommerce App Servers:,, - This is what I want to capture on (filtered on these exact IPs) I have tried 'host host' etc. There are other applications within this range, e.g. PayRoll App is on, and I don't want to see any of this in my capture. Therefore 'net' to capture the whole range will not work for me.

an anyone provide me the syntax? Is it even possible?

Yes, you can use the capture filter:

host or host or host

Or even shorter:

host or or

If you want to capture a whole subnet, but one IP, you can use:

net and not host

Hope this helps!

answered 13 Jun '11, 08:14

This codes not working host ip and others I using a 1.12.8 version

(10 Nov '15, 07:47) harutokawasaki

What's not working? Note you should really raise your own question, not piggy back on another, and in it show the exact filter that doesn't work for you

(10 Nov '15, 08:05) grahamb
