sara vanan wrote: > > I saw that today only and I tried executing in Linux OS but it gives > error( Invalid filter).
Note that "dns && ip.addr == 192.168.16.67 && ip.addr == 192.168.16.106" is a *display* filter which is different from a *capture* filter. E.g., you can type it into the filter field in Wireshark or use it with the "-R" command line argument to Wireshark or 'tshark' but you cannot use it with the "-f" argument to either program. HTH, -J _______________________________________________ Wireshark-dev mailing list Wireshark-dev@wireshark.org http://www.wireshark.org/mailman/listinfo/wireshark-dev