http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1109
Summary: Ability to do "greater than" display filter on http
content lenth
Product: Wireshark
Version: 0.99.3
Platform: PC
OS/Version: Windows Server 2003
Status: NEW
Severity: Enhancement
Priority: Low
Component: Wireshark
AssignedTo: wireshark-bugs@xxxxxxxxxxxxx
ReportedBy: mwreynolds@xxxxxxxxx
I am a big fan of wireshark and in particular the rich TCP reassemble and http
dissector functionality.
I often have a need to open large http traces and use a display filter to
identify the reassembled object downloads, such as jpg files.
Often there are many such http 200 status reassembles in a trace, and I would
like to be able to filter out the many tiny downloads to identify larger items.
So, I would like to be able to do something like (http.content_length >=
10000).
Wireshark actually allows me to apply that as a display filter, but it doesn't
work as expected. From my uneducated standpoint it appears that this may be
because the http dissector treats this field as a 22 byte string, rather than
extracting the value and treating it as an integer.
So, it would be really nice if this were treated as a number and the
functionality that would provide.
Thanks for the great tool!
--
Configure bugmail: http://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.