Wireshark-bugs: [Wireshark-bugs] [Bug 3791] Filter expression syntax needs to handle tunneling b
Date: Mon, 22 Nov 2010 14:49:10 -0800 (PST)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3791

--- Comment #2 from Chris Maynard <christopher.maynard@xxxxxxxxx> 2010-11-22 14:49:08 PST ---
Maybe it would be possible to extend the display filters somehow to be able to
filter based on something like what tshark provides with its
"-Eoccurrence=f|l|a" capabilities?  Today, essentially Wireshark filters
packets using "-Eoccurrence=a", but if that feature can be added to tshark,
then at least in theory it could be added to Wireshark?

This still might not be sufficient in some cases though, e.g. if you had more
than 2 levels of encapsulation/tunneling and wanted the filter results as it
only applies to one in the middle.  Still, it might get us part of the way
there.  Or maybe it would also be possible to change/extend the syntax to
suport the equivalent of "-Eoccurrence=#", where # is simply the nth
occurrence.

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.