This is our old Q&A Site. Please post any new questions and answers at

I am new to wireshark filtering. I didn't found any serious wireshark filtering tutorial. I want to create a capture filter every frames sent by to by Ethernet using http protocol.

I tried:

http eth source dest

Yet, It didn't worked and was turn to red. CCan you help me write this command? If you have any link about a serious wireshark filtering commands I would be ery glad to hear about it!

asked 22 Jun '16, 01:19

AntoineKRA's gravatar image

accept rate: 0%

As the capture filter is "executed" by the libpcap/WinPcap/NPcap module, the documentation (not exactly a tutorial) is here, not at the Wireshark wiki.

In your case, the correct syntax would be ip and src host and dst host and tcp port 80, where ip is a shortcut for ether proto ip.

Beware - in Qt version of Wireshark (the default one since 2.0.x), you have to choose an interface before starting to fill in the capture filter field, otherwise the field will be red even if the syntax is correct.

permanent link

answered 22 Jun '16, 04:08

sindy's gravatar image

accept rate: 24%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 22 Jun '16, 01:19

question was seen: 1,961 times

last updated: 22 Jun '16, 04:08

p​o​w​e​r​e​d by O​S​Q​A