This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

what is the difference between capture filter and display filter?

asked 01 Oct '11, 01:07

Terrestrial%20shark's gravatar image

Terrestrial ...
96212829
accept rate: 42%


A capture filter is used to select which packets should be saved to disk while capturing. For capture filters wireshark uses the BPF syntax. BPF is module that runs in the kernel and can therefor maintain high rates of capturing because the packets do not have to move from kernel space to user space when filtering. The things that can be filtered on are predefined and limited (compared to display filters) as full dissection has not been done on the packets.

Display filters are used to change the view of a capture file. They take advantage of the full dissection of all packets. This makes it possible to do very complex and advanced filtering when analyzing a network tracefile.

permanent link

answered 01 Oct '11, 02:02

SYN-bit's gravatar image

SYN-bit ♦♦
17.1k957245
accept rate: 20%

edited 01 Oct '11, 02:04

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×349

question asked: 01 Oct '11, 01:07

question was seen: 25,621 times

last updated: 01 Oct '11, 02:04

p​o​w​e​r​e​d by O​S​Q​A