This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi everybody !

I search to create a capture filtre with the protocol SIP but i don't know like to do. My release Wireshark is 2.2.6 and when i write in the field Capture Filter "SIP", it not work, I can not start.

Can you help me ?

Thank you very much.

Bye.

JbOne

asked 09 May '17, 05:39

JbOne73's gravatar image

JbOne73
6112
accept rate: 0%


Capture filters also known as BPF filters, only work at up to protocols such as TCP and UDP. To filter on protocols running atop those you have to either use port filters if your traffic always uses a fixed number of ports, or fall back to checking specific offsets in packets which is very error prone.

The Wiki page on Capture Filters has a discussion on capture filters for SIP using port based filters, and an offset based one for RTP traffic.

permanent link

answered 09 May '17, 05:44

grahamb's gravatar image

grahamb ♦
19.8k330206
accept rate: 22%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×109

question asked: 09 May '17, 05:39

question was seen: 5,590 times

last updated: 09 May '17, 05:44

p​o​w​e​r​e​d by O​S​Q​A