https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6863
--- Comment #14 from Chris Maynard <christopher.maynard@xxxxxxxxx> 2012-06-11 11:48:33 PDT ---
(In reply to comment #12)
> The unfiltered trace is the same as the filtered trace, just saved as
> 'Displayed' with that filter.
My results are the same as Jeff's.
And actually I'm a bit confused, because at first there seemed to be missing
RTP packets after filtering, but now you're saying that the new filtered file
is actually the same as the unfiltered file? So did you upgrade from 1.6.5 to
a newer version of Wireshark and now the behavior has changed? If so, what
version are you running now?
And I apologize for asking, but I must ... with 1.6.x, after applying your
filter and choosing "File -> Save as", did you remember to manually select
"Displayed" from the Packet Range? In 1.6.x, the default was to save all
captured packets rather than all displayed packets, so if you had forgotten to
select "Displayed", then the new file would be the same as the old file. (That
behavior will change in 1.8.x so that the displayed packets will be the default
packets to be saved.)
> I have found that if I take off the "!ip.addr==198.6.1.65 "
> part of the filter that it does not happen.
Could it be that you remembered to select "Displayed" from the Packet Range in
this case?
--
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are watching all bug changes.