8 min read 1661 words Updated Sep 12, 2026 Created Sep 12, 2026

official Display Filter Reference"

Syntax

Analyze -> Display Filters
Analyze -> Display Filter Expression

 the Display Filter Expressions menu provides an easy-to-use display filter builder guide. It is available under the "Analyse --> Display Filter Expression" menu.

Wireshark supports decimal and hexadecimal values in filtering.

Comparison operators

EnglishC-likeDescriptionExampleAlias
eq==Equal (any if more than one)ip.src == 10.0.0.5any_eq
ne!=Not equal (all if more than one)ip.src != 10.0.0.5all_ne
===Equal (all if more than one)ip.src === 10.0.0.5all_eq
!==Not equal (any if more than one)ip.src !== 10.0.0.5any_ne
gt>Greater thanframe.len > 10
lt<Less thanframe.len < 128
ge>=Greater than or equal toframe.len ge 0x100
le<=Less than or equal toframe.len <= 0x20
containsProtocol, field or slice contains a valuesip.To contains "a1762"
matches~Protocol or text field matches a Perl-compatible regular expressionhttp.host matches "acme\\.(org|com|net)"

Logical Expressions

Wireshark supports boolean syntax. You can create display filters by using logical operators as well.

EnglishC-LikeDescriptionExample
and&&Logical AND(ip.src 10.10.10.100) AND (ip.src 10.10.10.111)
or|Logical OR(ip.src 10.10.10.100) OR (ip.src 10.10.10.111)
not!Logical NOT!(ip.src == 10.10.10.222)

Note: Usage of !=value is deprecated; using it could provide inconsistent results. Using the !(value) style is suggested for more consistent results.

Advanced operators and functions

contains

search for a value inside packets

examples

http.server contains "Apache"

matches

examples

http.host matches "\.(php|html)"

# Find all hostnames that contain "php" and "html": 
# List all  HTTP packets where packets' "host" fields match keywords ".php" or ".html".

in

examples

tcp.port in {80 443 8080}

# Find all packets that use ports 80, 443 or 8080.

upper, lower

Convert a string to upper or lower

examples

upper(http.server) contains "APACHE"

lower(http.server) contains "apache"

string

Convert a non-string value to a string.

examples

string(frame.number) matches "[13579]$"

# Convert all "frame number" fields to string values, and list frames end with odd values.

bookmarks

  • use the bookmark button to the left of the filter input to save a filter.
  • use the '+' sign to the right of the filter input to add a button for a filter.

ip

ip filter examples

FilterDescription
ipShow all IP packets.
ip.addr 10.10.10.111Show all packets containing IP address 10.10.10.111.
ip.addr 10.10.10.0/24Show all packets containing IP addresses from 10.10.10.0/24 subnet.
ip.src 10.10.10.111Show all packets originated from 10.10.10.111
ip.dst 10.10.10.111Show all packets sent to 10.10.10.111

see communication between 2 ip addresses:
ip.addr [ip1] && ip.addr [ip2]
or
right click on a packet and choose 'conversation filter'

DNS

DNS Records

FilterDescription
dnsShow all DNS packets
dns.flags.response 0Show all DNS requests
dns.flags.response 1Show all DNS responses
dns.qry.type 1Show all DNS "A" records
(dns.qry.type 1) and (dns.flags.response == 0)Show all DNS requests for "A" records

TCP and UDP

tcp and udp filter examples

FilterDescription
tcp.port 80Show all TCP packets with port 80
tcp.srcport 1234Show all TCP packets originating from port 1234
tcp.dstport 80Show all TCP packets sent to port 80
udp.dstport 5353Show all UDP packets sent to port 5353
tcp.flags & 0x02match all packets that contain the “tcp.flags” field with the 0x02 bit, i.e., the SYN bit, set.

TCP

Traffic Recognition#TCP SYN scan filter
Traffic Recognition#TCP connect scan filter

TCP Flags

NotesWireshark Filters
Global search.- tcp
- udp
- Only SYN flag

- SYN flag is set. The rest of the bits are not important.
- tcp.flags 2

- tcp.flags.syn 1
- Only ACK flag.

- ACK flag is set. The rest of the bits are not important.
- tcp.flags 16

- tcp.flags.ack 1
- Only SYN, ACK flags.

- SYN and ACK are set. The rest of the bits are not important.
- tcp.flags 18

- (tcp.flags.syn 1) and (tcp.flags.ack 1)
- Only RST flag.

- RST flag is set. The rest of the bits are not important.
- tcp.flags 4

- tcp.flags.reset 1
- Only RST, ACK flags.

- RST and ACK are set. The rest of the bits are not important.
- tcp.flags 20

- (tcp.flags.reset 1) and (tcp.flags.ack 1)
- Only FIN flag

- FIN flag is set. The rest of the bits are not important.
- tcp.flags 1

- tcp.flags.fin 1

UDP

UDP scan patterns:
icmp.type3 and icmp.code3

  • icmp.type 3 → Destination Unreachable
  • icmp.code 3 → specifically Port Unreachable

Which UDP ports in the 55-70 port range are open?
udp.dstport >=55 and udp.dstport <= 70

  • then inspect which ports do not have an ICMP unreachable response

http

In HTTP, the HOST header identifies the server/domain the client is trying to reach, not the client's hostname.

For example, your browser might send:

GET /index.html HTTP/1.1
Host: acme.com

to request the page index.html at acme.com

FilterDescription
httpShow all HTTP packets
http.response.code 200Show all packets with HTTP response code "200"
http.request.method "GET"Show all HTTP GET requests
http.request.method == "POST"Show all HTTP POST requests

arp

NotesWireshark filter
Global search- arp
Opcode 1: ARP requests.

Opcode 2: ARP responses.

**Hunt:**Arp scanning

**Hunt:**Possible ARP poisoning detection

**Hunt:**Possible ARP flooding from detection:
- arp.opcode 1

- arp.opcode 2

- arp.dst.hw_mac00:00:00:00:00:00

- arp.duplicate-address-detected or arp.duplicate-address-frame

- ((arp) && (arp.opcode 1)) && (arp.src.hw_mac == target-mac-address)

SMTP

SMTP

  • status codes
Field nameDescriptionTypeVersions
smtp.auth.passwordPasswordCharacter string1.10.0 to 4.6.8
smtp.auth.usernameUsernameCharacter string1.10.0 to 4.6.8
smtp.auth.username_passwordUsername/PasswordCharacter string2.0.1 to 4.6.8
smtp.base64_decodebase64 decode failed or is not enabled (check SMTP preferences)Label2.0.1 to 4.6.8
smtp.command_lineCommand LineCharacter string1.8.0 to 4.6.8
smtp.data.fragmentDATA fragmentFrame number1.0.0 to 4.6.8
smtp.data.fragment.countDATA fragment countUnsigned integer (32 bits)1.6.0 to 4.6.8
smtp.data.fragment.errorDATA defragmentation errorFrame number1.0.0 to 4.6.8
smtp.data.fragment.multiple_tailsDATA has multiple tail fragmentsBoolean1.0.0 to 4.6.8
smtp.data.fragment.overlapDATA fragment overlapBoolean1.0.0 to 4.6.8
smtp.data.fragment.overlap.conflictsDATA fragment overlapping with conflicting dataBoolean1.0.0 to 4.6.8
smtp.data.fragment.too_long_fragmentDATA fragment too longBoolean1.0.0 to 4.6.8
smtp.data.fragmentsDATA fragmentsLabel1.0.0 to 4.6.8
smtp.data.reassembled.inReassembled DATA in frameFrame number1.0.0 to 4.6.8
smtp.data.reassembled.lengthReassembled DATA lengthUnsigned integer (32 bits)1.4.0 to 4.6.8
smtp.eomEOMLabel2.0.0 to 4.6.8
smtp.messageMessageCharacter string1.8.0 to 4.6.8
smtp.reqRequestBoolean1.0.0 to 4.6.8
smtp.req.commandCommandCharacter string1.0.0 to 4.6.8
smtp.req.parameterRequest parameterCharacter string1.0.0 to 4.6.8
smtp.responseResponseCharacter string1.8.0 to 4.6.8
smtp.response.codeResponse codeUnsigned integer (32 bits)1.0.0 to 4.6.8
smtp.response.code.unexpectedUnexpected response code in multiline responseLabel3.2.0 to 4.6.8
smtp.rspResponseBoolean1.0.0 to 4.6.8
smtp.rsp.parameterResponse parameterCharacter string1.0.0 to 4.6.8

IMF - Internet Message Format

https://www.wireshark.org/docs/dfref/i/imf.html

802.11 filters

Beacons (find networks)
wlan.fc.type_subtype 8

Probe requests (clients searching)
wlan.fc.type_subtype 4

Authentication
wlan.fc.type_subtype 11

Deauthentication attacks
wlan.fc.type_subtype 12

EAPOL (WPA handshake)
eapol

fc = frame control

auth frames:
wlan.fc.type_subtype == 11

Examples

Find all Microsoft IIS servers. What is the number of packets that did not originate from "port 80"?:
(http.server contains "IIS") and !(tcp.port == 80)

Which UDP port in the 55-70 port range is open?
udp.dstport >= 55 and udp.dstport <= 70 and !(icmp.code==3)

find all FTP responses in the x3x series
string(ftp.response.code) matches "^[0-9]3[0-9]"


related

Traffic Recognition