In the first and second chapters, we talked about how to install Wireshark, how to configure it for basic and smart operations, and where to locate it on the network. In this chapter and the next one, we will talk about capture filters and display filters.
It is important to distinguish between these two types of filters:
- Capture filters are configured before we start to capture data, so only data that is approved by the filters will be captured. All other data will be lost. These filters are described in this chapter.
- Display filters are filters that filter data after it has been captured. In this case, all data is captured and you configure what data you wish to display. These filters are described in the next chapter.
Capture filters are based on the tcpdump syntax presented in the libpcap/WinPcap library, while the display filters syntax was presented some years...