In answer to "the wireshark's filter can directly apply on libpcap's filter?", the answer is "no" - Wireshark display filters and libpcap capture filters are processed by different code and have different syntaxes and capabilities (Wireshark display filters are much more powerful than libpcap filters, but Wireshark is bigger and does a LOT more work to support that).

Discovering IPv6 with Wireshark Subnet Prefix & Mask From Router Advertisements (O-Flag=0 M-Flag=0) From Router Advertisements (O-Flag=1 / M-Flag=0) From Router Advertisements (O-Flag=1 / M-Flag=1) Interface Identifier Auto Configuration Auto Configuration From DHCPv6 Server DNS, NTP address etc. Manual Configuration From DHCPv6 Server From DHCPv6 Server O = Other Flag / M

Capture Filter for Specific IP in Wireshark. Use the following capture filter to capture only the packets that contain a specific IP in either the source or the destination: host Capture Filter for Specific Source IP in Wireshark. Use the following capture filter to capture only the packets originating from a specific host:

An overview of the capture filter syntax can be found in the User's Guide. A complete reference can be found in the expression section of the pcap-filter(7) manual page. Wireshark uses the same syntax for capture filters as tcpdump, WinDump, Analyzer, and any other program that uses the libpcap/WinPcap library.

How to capture packets. This is Wireshark's main menu: To start a capture, click the following icon: A new dialog box should have appeared.

Designing Capture Filters - Ethereal/Wireshark. Designing capture filters for Ethereal/Wireshark requires some basic knowledge of tcpdump syntax. Designing the Filters Using Tcpdump Syntax. Tcpdump provides several primitives for easy filter design. Think of a primitive as a macro or keyword for a predefined filter.

Actually, if you want to minimize the temporary file, you could add a filter to the capture itself: Capture -> Options -> Capture filter "host" (or whatever is the IP you want to filter.