First time here? Check out the FAQ!
THIS IS A TEST INSTANCE. Feel free to ask and answer questions, but take care to avoid triggering too many notifications.
0

search packet

Hello:

is there anyway to filter all the packets with specific word in "info" column. basically i have username abc pops up on info column. i can search one by one packet and see the username but i wanted to see all the packets with that username .. i tried frame matches username but not successful thanks

quest4answer's avatar
11
quest4answer
asked 2021-05-11 22:16:50 +0000
edit flag offensive 0 remove flag close merge delete

Comments

add a comment see more comments

2 Answers

1

There is a Lua plugin available that will add another column you can search on.

filtcols: A post-dissector to allow filtering on Protocol and Info columns

Chuckc's avatar
3k
Chuckc
answered 2021-05-11 22:59:32 +0000
edit flag offensive 0 remove flag delete link

Comments

that worked .. thanks

quest4answer's avatar quest4answer (2021-05-12 19:44:31 +0000) edit
add a comment see more comments
0

This is a fairly frequent question, and no you can't filter by column content. You can filter by field and as (almost) everything that is added to the info column is also a field somewhere, you just need to identify the appropriate field.

The general approach to this is to select one of the packets, (by manually reviewing the info column), and then in the packet details pane locate the field that contains the required information. Right click the field, select Apply As Filter -> Selected and the appropriate filter expression will be added to the filter bar and the packet list will be filtered according to the expression.

grahamb's avatar
23.8k
grahamb
answered 2021-05-12 08:07:45 +0000
edit flag offensive 0 remove flag delete link

Comments

add a comment see more comments

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account. This space is reserved only for answers. If you would like to engage in a discussion, please instead post a comment under the question or an answer that you would like to discuss.

Add Answer