This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hello,

When trying to compare two capture-files (following this article http://www.wireshark.org/docs/wsug_html_chunked/ChStatCompareCaptureFiles.html) I get an error-message when trying to run the compare. It seems that the filter-value is pre-populated even though I haven't selected anything.

The error-message I get is: Filter "000000" is invalid - "000000" is neither a field nor a protocol name.

If I click OK and try to apply a filter, I get the same error again, but this time it might look like this: Filter "000000,tcp.stream eq 1139" is invalid - Syntax error.

Version/OS: Version 1.4.1 (SVN Rev 34476 from /trunk-1.4) Running on 64-bit Windows 7, build 7600, with WinPcap version 4.1.2 (packet.dll version 4.1.0.2001), based on libpcap version 1.0 branch 1_0_rel0b (20091008), GnuTLS 2.8.5, Gcrypt 1.4.5, without AirPcap.

Anyone seen this problem before and found a resolution??

Regards

asked 15 Oct '10, 00:00

p0wned's gravatar image

p0wned
1111
accept rate: 0%

Did you have 000000 in the Filter: box in the main window? If so, then that will be copied to the filter box in the "Compare" window (you can edit that filter box and remove the copied filter).

(17 Oct '10, 12:12) Guy Harris ♦♦
Be the first one to answer this question!
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×349
×12
×1

question asked: 15 Oct '10, 00:00

question was seen: 2,463 times

last updated: 17 Oct '10, 12:12

p​o​w​e​r​e​d by O​S​Q​A