This is our old Q&A Site. Please post any new questions and answers at

Hi everybody !

I search to create a capture filtre with the protocol SIP but i don't know like to do. My release Wireshark is 2.2.6 and when i write in the field Capture Filter "SIP", it not work, I can not start.

Can you help me ?

Thank you very much.



asked 09 May '17, 05:39

JbOne73's gravatar image

accept rate: 0%

Capture filters also known as BPF filters, only work at up to protocols such as TCP and UDP. To filter on protocols running atop those you have to either use port filters if your traffic always uses a fixed number of ports, or fall back to checking specific offsets in packets which is very error prone.

The Wiki page on Capture Filters has a discussion on capture filters for SIP using port based filters, and an offset based one for RTP traffic.

permanent link

answered 09 May '17, 05:44

grahamb's gravatar image

grahamb ♦
accept rate: 22%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 09 May '17, 05:39

question was seen: 5,590 times

last updated: 09 May '17, 05:44

p​o​w​e​r​e​d by O​S​Q​A