|
EtherealRe: [Ethereal-users] display filters, how do I say OR? and how do I see only the initial connections |
|
||
------------------- The Ethereal project is being continued at a new site. Please go to http://www.wireshark.org and subscribe to wireshark-users@xxxxxxxxxxxxxx Don't forget to unsubscribe from this list at http://www.ethereal.com/mailman/listinfo/ethereal-users -------------------
------------------------------------------------------------------------
1)
how do I say OR ?
AND is &&
for example, I want to say tcp.dstport != 3389 "OR" tcp.srcport != 3389
In Wireshark, just as AND is &&, OR is...
...||.
2)
how do I see only the initial connections? and just incoming or just outgoing?
is there an easier way than this? (i'm not even sure if this is right)
my ip is 192.168.0.2
for incoming-
tcp.flags.syn == 1 && tcp.flags.ack==0 && ip.src != 192.168.0.2
for outgoing- tcp.flags.syn == 1 && tcp.flags.ack==0 && ip.src == 192.168.0.2
Ditto.
Powered by MHonArc 2.6.10