Wireshark-users: [Wireshark-users] Counting packets with a matching payload
From: "Scott Sheppard" <scott.sheppard@xxxxxxxxxxxxxxxxx>
Date: Wed, 6 Feb 2008 18:42:10 -0000
Hello 

I have a data set with 50,000 packets in it. Many of them have a TCP/IP
packet with a payload that follows a pattern. The pattern is a 1024 byte
payload with 55 aa 55 aa etc hex in it. I want to filter this data set and
count how many packets have this pattern it is. 

Any thoughts?

I can do this with a decode filter on my clearsight and Network Instruments
analyzers but I am stuck with how to do this in WS. 

Thanks

Scott Sheppard
ATT Labs