Wiresshark

1.给特定报文标注特殊颜色

[View]>[Coloring Rules] 然后就可以设定标注规则和颜色啦.

2.wireshark中TCP索引解释

tcp.stream eq tcp streamindex
the stream index is an internal Wireshark mapping to: [IP address A, TCP port A, IP address B, TCP port B]
All the packets for the same tcp.stream value should have the same values for these fields (though the src/dest will be switched for A->B and B->A packets)
see the Statistics/Conversations/TCP tab in Wireshark to show a summary of these streams

 

你可能感兴趣的:(shark)