capture packets from single ip address

  • retag add tags

Ho do I capture packets from single ip address. I typed IP.addr==192.168.42.xxx in the filter. Then sent emails from this address. No packets showed up

mcmahanj's avatar
1
mcmahanj
asked 2020-05-01 21:25:01 +0000
edit flag offensive 0 remove flag close merge delete

Comments

What is your capture setup - wired or wireless?
Have you verified that you can see packets from that source?

Chuckc's avatar Chuckc (2020-05-01 22:27:03 +0000) edit

How did you send emails? Note the filter you have given is a display filter, not a capture filter. Regardless, you have to be able to capture the traffic you want without any filtering before you can apply a filter to restrict what is captured\displayed.

grahamb's avatar grahamb (2020-05-02 15:41:26 +0000) edit

Are you sending the emails from the machine running Wireshark or not?

If not, what type of network are the two machines on - Ethernet, Wi-Fi, or something else?

Guy Harris's avatar Guy Harris (2020-05-02 20:11:48 +0000) edit
add a comment see more comments