Wireshark-users: Re: [Wireshark-users] Display filters for application protocols
From: Chris Maynard <chris.maynard@xxxxxxxxx>
Date: Tue, 8 Mar 2011 15:28:56 +0000 (UTC)
Lukáš Oliva <olivalukas@...> writes:

> I am doing some testing for the Diameter protocol and I noticed
> interesting behaviour of the display filters. I noticed that if I run
> 
> tshark -r mypcap.pcap -R "diameter.cmd.code==302"
> 
> then the output contains afterwards also Diameter packets with
> different diameter.cmd.code. I am not sure if it is actually a bug and
> how tshark handles this filtering for application protocols.

Maybe you could post a [small] capture file that depicts the problem?