通配符
ip.host matches “192.168.2.*”
一般filter
Ip.addr== 192.168.1.1
ip.src == 192.168.199.101
ip.dst==192.168.199.101
Tcp.port=80
Tcp.srcport tcp.dstport tcp.flag.syn tcp.flag.ack
Filter协议
直接在filter里输入协议名称:如tcp或dns或tls或http
统计坏包率
tcp.analysis.out_of_order || tcp.analysis.duplicate_ack || tcp.analysis.spurious_retransmission || tcp.analysis.lost_segment
操作符(&& || !)
ip.addr == 192.168.199.101 && tcp.port ==80
tcp.port in {80 443 8080}
wireshark笔记
最新推荐文章于 2024-08-11 16:46:26 发布