Wireshark-users: [Wireshark-users] Capture Filter Help
From: James Pifer <jep@xxxxxxxxxxxxxxxx>
Date: Wed, 06 Feb 2008 13:51:43 -0500
Hi. I've been googling and using the wiki but I can't figure out if this
is possible. 

I'm trying setup a capture filter to capture only data where the ip
address contains a certain part of an ip address. We have a lot of
servers on a distributed network that have standard addresses. 

For example, I'd like to capture data on port 137 if the ip address is
like 192.xxx.xxx.11 where xxx can be anything. 

Can this be done in a capture filter? Looks like it can be done in a
display filter, but I really don't want that. 

Any help is appreciated. 

Thanks,
James