diff options
Diffstat (limited to 'docbook/wsug_src/wsug_advanced.adoc')
-rw-r--r-- | docbook/wsug_src/wsug_advanced.adoc | 5 |
1 files changed, 5 insertions, 0 deletions
diff --git a/docbook/wsug_src/wsug_advanced.adoc b/docbook/wsug_src/wsug_advanced.adoc index e28a416775..9ca624ab66 100644 --- a/docbook/wsug_src/wsug_advanced.adoc +++ b/docbook/wsug_src/wsug_advanced.adoc @@ -720,6 +720,11 @@ data transfer will be found with a longer filter as closing a connection can be associated with FIN or RST packets, or even both : 'tcp.completeness==31 or tcp.completeness==47 or tcp.completeness==63' +Another way to select specific conversation values is to filter on the +tcp.completeness.str field. Thus, 'tcp.completeness.str matches "(R.*|F)[^D]ASS"' +will find all 'Complete, NO_DATA' conversations, while the 'Complete, WITH_DATA' +ones will be found with 'tcp.completeness.str matches "(R.*|F)DASS"'. + [#ChAdvTimestamps] === Time Stamps |