[SIPForum-discussion] Wireshark Display Filter
Tim Garey
tim.garey at myfairpoint.net
Tue Oct 15 15:28:20 UTC 2013
I have a large pcap file with about 7 active calls. I can see on one
particular call there is a problem and
need to find out when in the trace the RTP stream ends for this call. I
have identified where it starts
and ports being used, but it seems nearly impossible to find where it ends
as the source/dest addresses
are the same for all calls.
Is there a way to create a Wireshark display filter to show only the RTP
stream with port = 52560 to IP-address1.
This would help greatly in troubleshooting
Thanks.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://sipforum.org/pipermail/discussion/attachments/20131015/1cc20814/attachment-0002.html>
More information about the discussion
mailing list