This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

What does the 8 stand for in (tcp.stream eq 8)?

0

I just can't figure out what the 8 stands for in (tcp.stream eq 8)?

asked 26 Oct '11, 07:42

0xffff0's gravatar image

0xffff0
6113
accept rate: 0%


One Answer:

2

It indicates that this is the 8th TCP or UDP stream found in the trace.

Before we had stream numbers a filter to identify the stream would specify a pair of IP addresses and port numbers, resulting in much longer display filters.

answered 26 Oct '11, 08:57

packethunter's gravatar image

packethunter
2.1k71548
accept rate: 8%

I.e., the 8 has no deep significance - it's just a number that Wireshark uses internally.

(26 Oct '11, 10:53) Guy Harris ♦♦

When tcp.stream was implemented, the number had no significance and would show some gaps. In recent (development) versions of Wireshark the number represents order in which wireshark detected tcp streams, the first gets tcp.stream==0, the next tcp.stream==1 etc.

(08 Nov '11, 03:10) SYN-bit ♦♦