[SIPForum-discussion] Wireshark Display Filter

Tim Garey tim.garey at myfairpoint.net
Tue Oct 15 15:28:20 UTC 2013

I have a large pcap file with about 7 active calls.  I can see on one
particular call there is a problem and

need  to find out when in the trace the RTP stream ends for this call. I
have identified where it starts

and ports being used, but it seems nearly impossible to find where it ends
as the source/dest addresses

are the same for all calls.


Is there a way to create a  Wireshark display filter to show only the RTP
stream with port = 52560 to IP-address1.

This would help greatly in troubleshooting




-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://sipforum.org/pipermail/discussion/attachments/20131015/1cc20814/attachment-0002.html>

More information about the discussion mailing list