help on ethereal syntax

help on ethereal syntax

Post by Tricia Wan » Sat, 06 Oct 2001 15:52:28



what is the syntax for ethereal that selects packets with destination ip
address 10.0.1.50 and frame size greater than 400 bytes ?   thanks for the
help
 
 
 

help on ethereal syntax

Post by Brian Showalte » Sun, 07 Oct 2001 04:20:23


Which filter are you using?  The capture filter (Ctrl-K) uses tcpdump
syntax, which would be:

dst host 10.0.1.50 and greater 400

See man "tcpdump" for more info.

The display filter at the bottom of the main window uses a different
syntax, which would be:

ip.dst == 10.0.1.50 and frame.pkt_len > 400

See "man ethereal" for more info.


> what is the syntax for ethereal that selects packets with destination ip
> address 10.0.1.50 and frame size greater than 400 bytes ?   thanks for
> the help