Wireshark capture filter primitives include 'host <ip>' (source or destination), '[src|dst] host <ip>' and '[tcp|udp] [src|dst] port <port>', combined with and, or and not.

Checked 2026-09-24

Vendor
Wireshark
Product
Wireshark
Subsystem
capture filters
Deployment
on-premises
Region
not restricted
Release range
current as of 2026-09-24
Checked
2026-09-24

Sources

Cite this note

APA

WarmTransfer. (2026, September 24). Analysing a SIP call in Wireshark: source note sip-call-analysis-wireshark-capfilter-host-port. WarmTransfer. https://warmtransfer.net/knowledge/claims/sip-call-analysis-wireshark-capfilter-host-port

BibTeX

@misc{warmtransfer-claim-sip-call-analysis-wireshark-capfilter-host-port,
  title  = {Analysing a SIP call in Wireshark: source note sip-call-analysis-wireshark-capfilter-host-port},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/claims/sip-call-analysis-wireshark-capfilter-host-port},
  note   = {Source note sip-call-analysis-wireshark-capfilter-host-port, checked 2026-09-24}
}

Read in context