Wireshark-users: [Wireshark-users] Capture Filter Inquiry

From: Frank Barta <fbarta@xxxxxxxxx>
Date: Mon, 14 Dec 2009 10:13:30 -0500
Hello,

I was wondering if it would be possible to create a capture filter that will analyze the contents of a syslog packet and only write the packet to the file if it has a specific string in it.

IE. If the syslog message contains the word "reset", write packet to file.

Thanks!