Display Filter Reference
Wireshark's most powerful feature is its vast array of display filters
(over 105000 as of version 1.4.0). They let you drill
drill down to the exact traffic you want to see and are the basis of many
of Wireshark's other features, such as the coloring rules.
This is a reference. If you need help using display filters, please see
the wireshark-filter
and the User's Guide.
Index
1
2
3
6
9
A
B
C
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
1
2
3
6
9
A
aal1: ATM AAL1
(1.0.0 to 1.4.0, 0 fields)
aal3_4: ATM AAL3/4
(1.0.0 to 1.4.0, 0 fields)
agentx:
AgentX
(1.0.0 to 1.4.0, 31 fields)
aim_adverts: AIM Advertisements
(1.0.0 to 1.4.0, 0 fields)
aim_chat: AIM Chat Service
(1.0.0 to 1.4.0, 0 fields)
aim_chatnav: AIM Chat Navigation
(1.0.0 to 1.4.0, 0 fields)
aim_dir: AIM Directory Search
(1.0.0 to 1.4.0, 0 fields)
aim_email: AIM E-mail
(1.0.0 to 1.4.0, 0 fields)
aim_icq:
AIM ICQ
(1.0.0 to 1.4.0, 6 fields)
aim_invitation: AIM Invitation Service
(1.0.0 to 1.4.0, 0 fields)
aim_oft: AIM OFT
(1.0.0 to 1.4.0, 0 fields)
aim_popup: AIM Popup
(1.0.0 to 1.4.0, 0 fields)
aim_stats: AIM Statistics
(1.0.0 to 1.4.0, 0 fields)
aim_translate: AIM Translate
(1.0.0 to 1.4.0, 0 fields)
ams:
AMS
(1.0.0 to 1.4.0, 65 fields)
ansi_a_dtap: ANSI A-I/F DTAP
(1.0.0 to 1.4.0, 0 fields)
arcnet:
ARCNET
(1.0.0 to 1.4.0, 7 fields)
artnet:
Art-Net
(1.0.0 to 1.4.0, 142 fields)
asn1: ASN.1 decoding
(1.0.0 to 1.4.0, 0 fields)
B
bacp: PPP Bandwidth Allocation Control Protocol
(1.0.0 to 1.4.0, 0 fields)
bap: PPP Bandwidth Allocation Protocol
(1.0.0 to 1.4.0, 0 fields)
bittorrent:
BitTorrent
(1.0.0 to 1.4.0, 28 fields)
brdwlk:
Boardwalk
(1.0.0 to 1.4.0, 15 fields)
C
camel:
Camel
(1.0.0 to 1.4.0, 480 fields)
cba_acco_cb2: ICBAAccoCallback2
(1.0.0 to 1.4.0, 0 fields)
cba_acco_mgt2: ICBAAccoMgt2
(1.0.0 to 1.4.0, 0 fields)
cba_acco_server2: ICBAAccoServer2
(1.0.0 to 1.4.0, 0 fields)
cba_acco_server_srt: ICBAAccoServerSRT
(1.0.0 to 1.4.0, 0 fields)
cba_acco_sync: ICBAAccoSync
(1.0.0 to 1.4.0, 0 fields)
cba_browse:
ICBABrowse
(1.0.0 to 1.4.0, 20 fields)
cba_browse2: ICBABrowse2
(1.0.0 to 1.4.0, 0 fields)
cba_grouperror: ICBAGroupError
(1.0.0 to 1.4.0, 0 fields)
cba_grouperror_event: ICBAGroupErrorEvent
(1.0.0 to 1.4.0, 0 fields)
cba_ldev: ICBALogicalDevice
(1.0.0 to 1.4.0, 0 fields)
cba_ldev2: ICBALogicalDevice2
(1.0.0 to 1.4.0, 0 fields)
cba_pdev2: ICBAPhysicalDevice2
(1.0.0 to 1.4.0, 0 fields)
cba_pdev_pc: ICBAPhysicalDevicePC
(1.0.0 to 1.4.0, 0 fields)
cba_pdev_pc_event: ICBAPhysicalDevicePCEvent
(1.0.0 to 1.4.0, 0 fields)
cba_persist: ICBAPersist
(1.0.0 to 1.4.0, 0 fields)
cba_persist2: ICBAPersist2
(1.0.0 to 1.4.0, 0 fields)
cba_rtauto: ICBARTAuto
(1.0.0 to 1.4.0, 0 fields)
cba_rtauto2: ICBARTAuto2
(1.0.0 to 1.4.0, 0 fields)
cba_state: ICBAState
(1.0.0 to 1.4.0, 0 fields)
cba_state_event: ICBAStateEvent
(1.0.0 to 1.4.0, 0 fields)
cba_sysprop: ICBASystemProperties
(1.0.0 to 1.4.0, 0 fields)
cba_time: ICBATime
(1.0.0 to 1.4.0, 0 fields)
cbcp: PPP Callback Control Protocol
(1.0.0 to 1.4.0, 0 fields)
ccp: PPP Compression Control Protocol
(1.0.0 to 1.4.0, 0 fields)
ccsds:
CCSDS
(1.0.0 to 1.4.0, 25 fields)
cdpcp: PPP CDP Control Protocol
(1.0.0 to 1.4.0, 0 fields)
cipcco: CIP Connection Configuration Object
(1.4.0, 0 fields)
cipcls: CIP Class Generic
(1.4.0, 0 fields)
cipmr: CIP Message Router
(1.4.0, 0 fields)
clacse: ISO 10035-1 OSI Connectionless Association Control Service
(1.4.0, 0 fields)
cldap: Connectionless Lightweight Directory Access Protocol
(1.0.0 to 1.4.0, 0 fields)
clpres: ISO 9576-1 OSI Connectionless Presentation Protocol
(1.4.0, 0 fields)
clsp: ISO 9548-1 OSI Connectionless Session Protocol
(1.4.0, 0 fields)
comp_data: PPP Compressed Datagram
(1.0.0 to 1.4.0, 0 fields)
crtp:
CRTP
(1.0.0 to 1.4.0, 6 fields)
csm_encaps:
CSM_ENCAPS
(1.0.0 to 1.4.0, 54 fields)
D
data:
Data
(1.0.0 to 1.4.0, 3 fields)
data-l1-events: Layer 1 Event Messages
(1.2.0 to 1.4.0, 0 fields)
data-text-lines: Line-based text data
(1.0.0 to 1.4.0, 0 fields)
db-lsp-disc: Dropbox LAN sync Discovery Protocol
(1.4.0, 0 fields)
dcerpc:
DCE RPC
(1.0.0 to 1.4.0, 142 fields)
dcm:
DICOM
(1.0.0 to 1.2.0, 16 fields)
dcom:
DCOM
(1.0.0 to 1.4.0, 88 fields)
dhcpv6:
DHCPv6
(1.0.0 to 1.4.0, 20 fields)
diameter.3gpp.ipaddr: IPv4 Address
(1.0.0 to 1.0.1, 0 fields)
diameter.3gpp.mbms_required_qos_prio: Allocation/Retention Priority
(1.0.0 to 1.0.1, 0 fields)
diameter.3gpp.mbms_service_id: MBMS Service ID
(1.0.0 to 1.0.1, 0 fields)
diameter.3gpp.tmgi: TMGI
(1.0.0 to 1.0.1, 0 fields)
dicom:
DICOM
(1.2.0 to 1.4.0, 44 fields)
dlsw: Data Link SWitching
(1.0.0 to 1.4.0, 0 fields)
dnsserver:
DNS Server
(1.0.0 to 1.4.0, 141 fields)
drda:
DRDA
(1.0.0 to 1.4.0, 17 fields)
drsuapi:
DRSUAPI
(1.0.0 to 1.4.0, 415 fields)
E
echo:
Echo
(1.0.0 to 1.4.0, 3 fields)
ehs:
EHS
(1.2.0 to 1.4.0, 120 fields)
enttec:
ENTTEC
(1.0.0 to 1.4.0, 17 fields)
epm4: DCE/RPC Endpoint Mapper v4
(1.0.0 to 1.4.0, 0 fields)
eth:
Ethernet
(1.0.0 to 1.4.0, 8 fields)
etheric:
Etheric
(1.0.0 to 1.4.0, 27 fields)
F
fcip:
FCIP
(1.0.0 to 1.4.0, 26 fields)
fp:
FP
(1.0.0 to 1.4.0, 114 fields)
fp_hint:
FP Hint
(1.4.0, 20 fields)
frame:
Frame
(1.0.0 to 1.4.0, 20 fields)
ftp-data: FTP Data
(1.0.0 to 1.4.0, 0 fields)
G
g723:
G.723
(1.0.0 to 1.4.0, 2 fields)
giop-coseventcomm: Coseventcomm Dissector Using GIOP API
(1.0.0 to 1.4.0, 0 fields)
giop-cosnaming: Cosnaming Dissector Using GIOP API
(1.0.0 to 1.4.0, 0 fields)
giop-parlay: Parlay Dissector Using GIOP API
(1.0.0 to 1.4.0, 0 fields)
giop-tango: Tango Dissector Using GIOP API
(1.0.0 to 1.4.0, 0 fields)
goose:
GOOSE
(1.2.0 to 1.4.0, 53 fields)
gpef:
GPEF
(1.2.0 to 1.4.0, 8 fields)
gsm_a_ccch:
GSM CCCH
(1.0.0 to 1.4.0, 258 fields)
gsm_a_sacch:
GSM SACCH
(1.2.0 to 1.4.0, 1 field)
H
h221nonstd: H221NonStandard
(1.0.0 to 1.4.0, 0 fields)
h223_bitswapped: Bitswapped ITU-T Recommendation H.223
(1.0.0 to 1.4.0, 0 fields)
h248an:
H.248.7
(1.0.0 to 1.4.0, 13 fields)
h248chp:
H.248.10
(1.0.0 to 1.4.0, 2 fields)
h263data: ITU-T Recommendation H.263
(1.0.0 to 1.2.0, 0 fields)
h264:
H.264
(1.0.0 to 1.4.0, 128 fields)
h323:
H.323
(1.0.0 to 1.4.0, 27 fields)
hyperscsi:
HyperSCSI
(1.0.0 to 1.4.0, 6 fields)
I
ifcp:
iFCP
(1.0.0 to 1.4.0, 21 fields)
ilmi: ILMI
(1.0.0 to 1.4.0, 0 fields)
infiniband:
InfiniBand
(1.0.0 to 1.4.0, 405 fields)
ipars: International Passenger Airline Reservation System
(1.0.0 to 1.4.0, 0 fields)
ipcp: PPP IP Control Protocol
(1.0.0 to 1.4.0, 0 fields)
ipsictl:
IPSICTL
(1.2.0 to 1.4.0, 7 fields)
ipv6cp: PPP IPv6 Control Protocol
(1.0.0 to 1.4.0, 0 fields)
ipxwan:
IPX WAN
(1.0.0 to 1.4.0, 19 fields)
iscsi:
iSCSI
(1.0.0 to 1.4.0, 104 fields)
isdn:
ISDN
(1.0.0 to 1.4.0, 1 field)
isns:
iSNS
(1.0.0 to 1.4.0, 101 fields)
iuup:
IuUP
(1.0.0 to 1.4.0, 1323 fields)
J
juniper:
Juniper
(1.0.0 to 1.4.0, 18 fields)
jxta:
JXTA P2P
(1.0.0 to 1.4.0, 49 fields)
jxta.message: JXTA Message
(1.0.0 to 1.4.0, 0 fields)
K
k12:
K12xx
(1.0.0 to 1.4.0, 6 fields)
kerberos:
Kerberos
(1.0.0 to 1.4.0, 181 fields)
L
lane: ATM LAN Emulation
(1.0.0 to 1.4.0, 0 fields)
laplink:
Laplink
(1.0.0 to 1.4.0, 5 fields)
lcp: PPP Link Control Protocol
(1.0.0 to 1.4.0, 0 fields)
lwapp-cntl: LWAPP Control Message
(1.0.0 to 1.4.0, 0 fields)
lwapp-l3: LWAPP Layer 3 Packet
(1.0.0 to 1.4.0, 0 fields)
M
mac:
MAC
(1.4.0, 5 fields)
mac-lte:
MAC-LTE
(1.2.0 to 1.4.0, 112 fields)
malformed: Malformed Packet
(1.0.0 to 1.4.0, 0 fields)
mate: Meta Analysis Tracing Engine
(1.0.0 to 1.4.0, 0 fields)
media: Media Type
(1.0.0 to 1.4.0, 0 fields)
megaco:
MEGACO
(1.0.0 to 1.4.0, 47 fields)
message-http: Media Type: message/http
(1.0.0 to 1.4.0, 0 fields)
mibs:
MIBs
(1.0.3 to 1.0.6, 1.0.9 to 1.2.0, 1.2.1 to 1.4.0, 759 fields)
mms:
MMS
(1.0.0 to 1.4.0, 446 fields)
mp4v-es:
MP4V-ES
(1.2.0 to 1.4.0, 15 fields)
mpeg: Moving Picture Experts Group
(1.0.0 to 1.4.0, 0 fields)
mplscp: PPP MPLS Control Protocol
(1.0.0 to 1.4.0, 0 fields)
mplspwatmcell:
ATM Cell
(1.4.0, 1 field)
msnms: MSN Messenger Service
(1.0.0 to 1.4.0, 0 fields)
N
nbipx: NetBIOS over IPX
(1.0.0 to 1.4.0, 0 fields)
netbios:
NetBIOS
(1.0.0 to 1.4.0, 32 fields)
nfsacl:
NFSACL
(1.0.0 to 1.4.0, 11 fields)
nfsauth:
NFSAUTH
(1.0.0 to 1.4.0, 1 field)
nisplus:
NIS+
(1.0.0 to 1.4.0, 118 fields)
nmpi: Name Management Protocol over IPX
(1.0.0 to 1.4.0, 0 fields)
nw_serial: NetWare Serialization Protocol
(1.0.0 to 1.4.0, 0 fields)
O
oamaal: ATM OAM AAL
(1.0.0 to 1.4.0, 0 fields)
osi: OSI
(1.0.0 to 1.4.0, 0 fields)
osicp: PPP OSI Control Protocol
(1.0.0 to 1.4.0, 0 fields)
P
p3: X.411 Message Access Service
(1.4.0, 0 fields)
pap: PPP Password Authentication Protocol
(1.0.0 to 1.4.0, 0 fields)
pcnfsd:
PC NFS
(1.0.0 to 1.4.0, 15 fields)
pdcp-lte:
PDCP-LTE
(1.2.0 to 1.4.0, 105 fields)
pkcs-1:
PKCS#1
(1.0.0 to 1.4.0, 11 fields)
pkinit:
PKINIT
(1.0.0 to 1.4.0, 22 fields)
portmap:
Portmap
(1.0.0 to 1.4.0, 19 fields)
ppp_hdlc: PPP In HDLC-Like Framing
(1.0.0 to 1.4.0, 0 fields)
pppmux: PPP Multiplexing
(1.0.0 to 1.4.0, 0 fields)
pppmuxcp: PPPMux Control Protocol
(1.0.0 to 1.4.0, 0 fields)
pw_atm_n2o_nocw: ATM PW, N-to-one Cell Mode (no CW)
(1.2.0 to 1.4.0, 0 fields)
pw_hdlc_nocw_hdlc_ppp: HDLC-like framing for PPP
(1.2.0 to 1.4.0, 0 fields)
pwach: PW Associated Channel Header
(1.2.0 to 1.4.0, 0 fields)
pwethheuristic: Ethernet PW (CW heuristic)
(1.2.0 to 1.4.0, 0 fields)
pwethnocw: Ethernet PW (no CW)
(1.2.0 to 1.4.0, 0 fields)
pwmcw: PW MPLS Control Word (generic/preferred)
(1.2.0 to 1.4.0, 0 fields)
Q
q2931:
Q.2931
(1.0.0 to 1.4.0, 9 fields)
q931:
Q.931
(1.0.0 to 1.4.0, 46 fields)
q932:
Q.932
(1.0.0 to 1.4.0, 39 fields)
q933:
Q.933
(1.0.0 to 1.4.0, 23 fields)
qsig:
QSIG
(1.0.0 to 1.4.0, 744 fields)
R
radio: 802.11 radio information
(1.0.0 to 1.4.0, 0 fields)
raw: Raw packet data
(1.0.0 to 1.4.0, 0 fields)
raw_sigcomp: Decompressed SigComp message as raw text
(1.0.0 to 1.4.0, 0 fields)
redback:
Redback
(1.0.0 to 1.4.0, 9 fields)
remunk2: IRemUnknown2
(1.0.0 to 1.4.0, 0 fields)
ripng:
RIPng
(1.0.0 to 1.4.0, 2 fields)
rlc:
RLC
(1.4.0, 29 fields)
rlc-lte:
RLC-LTE
(1.2.0 to 1.4.0, 52 fields)
rmi:
Java RMI
(1.0.0 to 1.4.0, 10 fields)
rss:
rss
(1.0.0 to 1.4.0, 122 fields)
rstat:
RSTAT
(1.0.0 to 1.4.0, 4 fields)
rtcfg:
RTcfg
(1.0.0 to 1.4.0, 23 fields)
S
sadmind:
SADMIND
(1.0.0 to 1.4.0, 3 fields)
scsi:
SCSI
(1.0.0 to 1.4.0, 175 fields)
scsi_mmc:
SCSI_MMC
(1.0.0 to 1.4.0, 145 fields)
scsi_osd:
SCSI_OSD
(1.0.0 to 1.4.0, 82 fields)
scsi_sbc:
SCSI_SBC
(1.0.0 to 1.4.0, 72 fields)
scsi_smc:
SCSI_SMC
(1.0.0 to 1.4.0, 17 fields)
scsi_ssc:
SCSI_SSC
(1.0.0 to 1.4.0, 41 fields)
serialization: Java Serialization
(1.0.0 to 1.4.0, 0 fields)
sgimount: SGI Mount Service
(1.0.0 to 1.4.0, 0 fields)
short: Short Frame
(1.0.0 to 1.4.0, 0 fields)
sipfrag:
Sipfrag
(1.0.0 to 1.4.0, 1 field)
sna_xid: Systems Network Architecture XID
(1.0.0 to 1.4.0, 0 fields)
spnego-krb5: SPNEGO-KRB5
(1.0.0 to 1.4.0, 0 fields)
spray:
SPRAY
(1.0.0 to 1.4.0, 6 fields)
sscf-nni:
SSCF-NNI
(1.0.0 to 1.4.0, 2 fields)
sscop:
SSCOP
(1.0.0 to 1.4.0, 8 fields)
starteam:
StarTeam
(1.0.0 to 1.4.0, 17 fields)
synergy:
Synergy
(1.0.0 to 1.4.0, 59 fields)
T
t30:
T.30
(1.0.0 to 1.4.0, 103 fields)
t38:
T.38
(1.0.0 to 1.4.0, 38 fields)
tacacs:
TACACS
(1.0.0 to 1.4.0, 13 fields)
tacplus:
TACACS+
(1.0.0 to 1.4.0, 12 fields)
tcpcl: DTN TCP Convergence Layer Protocol
(1.4.0, 0 fields)
tdma: TDMA RTmac Discipline
(1.0.0 to 1.4.0, 0 fields)
telnet:
Telnet
(1.0.0 to 1.4.0, 10 fields)
trill:
TRILL
(1.4.0, 8 fields)
U
udpencap: UDP Encapsulation of IPsec Packets
(1.0.0 to 1.4.0, 0 fields)
unreassembled: Unreassembled Fragmented Packet
(1.0.0 to 1.4.0, 0 fields)
usb:
USB
(1.0.0 to 1.4.0, 75 fields)
user_dlt: DLT User
(1.0.0 to 1.4.0, 0 fields)
V
v52:
V5.2
(1.4.0, 66 fields)
vcdu:
VCDU
(1.2.0 to 1.4.0, 26 fields)
vines_arp: Banyan Vines ARP
(1.0.0 to 1.4.0, 0 fields)
vines_echo: Banyan Vines Echo
(1.0.0 to 1.4.0, 0 fields)
vines_frp: Banyan Vines Fragmentation Protocol
(1.0.0 to 1.4.0, 0 fields)
vines_icp: Banyan Vines ICP
(1.0.0 to 1.4.0, 0 fields)
vines_ipc: Banyan Vines IPC
(1.0.0 to 1.4.0, 0 fields)
vines_llc: Banyan Vines LLC
(1.0.0 to 1.4.0, 0 fields)
vines_rtp: Banyan Vines RTP
(1.0.0 to 1.4.0, 0 fields)
vines_spp: Banyan Vines SPP
(1.0.0 to 1.4.0, 0 fields)
vsncp: Vendor Specific Control Protocol
(1.4.0, 0 fields)
W
who:
Who
(1.0.0 to 1.4.0, 14 fields)
wpan-nonask-phy: IEEE 802.15.4 Low-Rate Wireless PAN non-ASK PHY
(1.2.0 to 1.4.0, 0 fields)
X
x.25:
X.25
(1.0.0 to 1.2.0, 17 fields)
x.29:
X.29
(1.0.0 to 1.2.0, 3 fields)
x11:
X11
(1.0.0 to 1.4.0, 6643 fields)
x25:
X.25
(1.2.0 to 1.4.0, 18 fields)
x29:
X.29
(1.2.0 to 1.4.0, 3 fields)
xyplex:
Xyplex
(1.0.0 to 1.4.0, 6 fields)
Y
Z
zrtp:
ZRTP
(1.2.0 to 1.4.0, 43 fields)