Wireshark Filters

Examples of Wireshark display filters:

To show only FTP (port 21) use the following

tcp.port eq 21

To show SMTP (port 25) and FTP (port 21) use the following

tcp.port eq 25 or 21

To show traffic to or from a particular IP address or address range use the following

ip.src==192.168.0.0/16 and ip.dst==10.1.1.1

When using the following filter
ip.addr==10.1.1.1
this is the same as
ip.src==10.1.1.1 or ip.dst=10.1.1.1

Examples of Wireshark Capture Filters

host 10.1.1.1