Understanding the expression builder
In addition to building simple display filters, Wireshark has the ability to create an expression that zeroes in on specific field values. To build an expression, go to Analyze and then select Display Filter Expression, as shown here:
Click the link to launch the expression builder. On the left-hand side, you will see a list of all of Wireshark's supported protocols, as shown in the following screenshot:
Wireshark is capable of dissecting hundreds of protocols with more added all the time, so the list will be long.
To further refine the filter, you can select from the four variables listed on the right-hand side:
- Relation: This is a list of comparison operators to compare a field value against another value using logical operators:
- is present: Indicates the selected field...