This is our old Q&A Site. Please post any new questions and answers at

Hello i have some problems with filter capturing. is it possible to capture only one ip address for example, i want to capture ip or, how can i do with it ?

asked 26 Jul '17, 23:57

Samann's gravatar image

accept rate: 0%

Capture filter syntax differs from display filter syntax, so to capture only, you need to use host

However, there is no capture syntax for fqdn (like for many reasons:

  • translation of fqdn to IP address is done using DNS, and there is no feedback from the dissection of the DNS response to the capture filter, leaving aside that the DNS responses are locally cached

  • a single fqdn may translate to several IP addresses (for load sharing and reliability purposes)

  • several fqdns may be hosted on a single IP address so you cannot determine which flow belongs to which fqdn by just the IP address.

permanent link

answered 27 Jul '17, 00:11

sindy's gravatar image

accept rate: 24%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 26 Jul '17, 23:57

question was seen: 878 times

last updated: 27 Jul '17, 00:11

p​o​w​e​r​e​d by O​S​Q​A