[SIPForum-discussion] Wireshark Display Filter

Stephen James sjames_1958 at yahoo.com
Tue Oct 15 23:50:14 UTC 2013

Open the detailed trace and right click on the IP address and select prepare as filter. Then select the port and right click and select prepare as filter AND selected. Then apply the filter. 

Sent from my iPhone

> On Oct 15, 2013, at 10:28, "Tim Garey" <tim.garey at myfairpoint.net> wrote:
> I have a large pcap file with about 7 active calls.  I can see on one particular call there is a problem and
> need  to find out when in the trace the RTP stream ends for this call. I have identified where it starts
> and ports being used, but it seems nearly impossible to find where it ends as the source/dest addresses
> are the same for all calls.
> Is there a way to create a  Wireshark display filter to show only the RTP stream with port = 52560 to IP-address1.
> This would help greatly in troubleshooting
> Thanks.
> _______________________________________________
> This is the SIP Forum discussion mailing list
> TO UNSUBSCRIBE, or edit your delivery options, please visit http://sipforum.org/mailman/listinfo/discussion
> Post to the list at discussion at sipforum.org
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://sipforum.org/pipermail/discussion/attachments/20131015/7bf9c3bf/attachment-0002.html>

More information about the discussion mailing list