Display Filter Reference: File

Protocol field name: file

Versions: 1.12.0 to 2.4.4

Back to Display Filter Reference

Field name Description Type Versions
file.coloring_rule.name Coloring Rule Name Character string 1.12.0 to 2.4.4
file.coloring_rule.string Coloring Rule String Character string 1.12.0 to 2.4.4
file.encap_type Encapsulation type Signed integer, 2 bytes 1.12.0 to 2.4.4
file.ignored File record is ignored Boolean 1.12.0 to 2.4.4
file.marked File record is marked Boolean 1.12.0 to 2.4.4
file.p_record_data Number of per-record-data Unsigned integer, 4 bytes 1.12.0 to 2.4.4
file.proto_name_and_key Protocol Name and Key Character string 2.0.0 to 2.4.4
file.record_len Record length Unsigned integer, 4 bytes 1.12.0 to 2.4.4
file.record_number Record Number Unsigned integer, 4 bytes 1.12.0 to 2.4.4
file.record_types File record types in frame Character string 1.12.0 to 2.4.4
Go Beyond with Riverbed Technology

Riverbed is Wireshark's primary sponsor and provides our funding. They also make great products that fully integrate with Wireshark.

I have a lot of traffic...

ANSWER: SteelCentral™ Packet Analyzer PE
  • • Visually rich, powerful LAN analyzer
  • • Quickly access very large pcap files
  • • Professional, customizable reports
  • • Advanced triggers and alerts
  • • Fully integrated with Wireshark and AirPcap™
Learn More

Buy Now

No, really, I have a LOT of traffic…

ANSWER: SteelCentral™ NetShark appliance
  • • Troubleshoot problems faster
  • • Quickly identify the applications running on your network
  • • Monitor your virtual machine traffic
Learn More