This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

display filter for established and active tcp connections only

0

display filter for established and active tcp connections only

asked 30 Jul '11, 00:57

ams's gravatar image

ams
1111
accept rate: 0%

2

I can guess what your question is, but it's better if you ask it.

(01 Aug '11, 16:13) helloworld

One Answer:

1

answered 01 Aug '11, 18:06

cmaynard's gravatar image

cmaynard ♦♦
9.4k1038142
accept rate: 20%

Um, ok.....

From the looks of that bug, it seems you're proposing that a solution (to a problem we don't yet really know) is to modify Wireshark to display the process associated with each packet.

(01 Aug '11, 19:39) helloworld

Yes, I believe that is the essence of the enhancement bug report. Gerald has done some experimentation with it (on Linux). Someone, (perhaps ams), may have an interest in it and want to fully implement it. Once that enhancement bug is resolved, I believe it would satisfy what I think ams desires, although it's hard to know for sure since you have to read between the lines to formulate what his question actually is.

(01 Aug '11, 19:46) cmaynard ♦♦