Wireshark-dev: [Wireshark-dev] how can i find the source code about display filter in wireshark
hi,all.
i am doing something about network traffic classification. when i use wireshark to collect some training data, i found it didn't work very well, sometimes. for example, when i type " tshark -r <file> -w <file> -R "http" " in command line and get some data about http(Hypertext Transfer Protocol). i found it also contains many p2p traffic. i am wondering how wireshark define the display filter "http". can i get some information about it in the source code? and how? can you tell me in which file?
i am sorry , my English is poor. i hope you all can understand my question, an give some help. thx.
--
Regards.
/jackyche