<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>filtering issue using wireshark and nRF52840 sniffer</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/98550/filtering-issue-using-wireshark-and-nrf52840-sniffer</link><description>Hello, 
 I&amp;#39;m using nRF52840 dongle as BLE sniffer and the plugin for wireshark. 
 
 capture example 
 
 if I want to filter one source : right clic, apply as a filter, selected, then this filter is created : 
 eth.src == 44:5c:e9:ab:a7:03 
 44:5c:e9:ab</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Thu, 13 Apr 2023 08:45:38 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/98550/filtering-issue-using-wireshark-and-nrf52840-sniffer" /><item><title>RE: filtering issue using wireshark and nRF52840 sniffer</title><link>https://devzone.nordicsemi.com/thread/420137?ContentTypeID=1</link><pubDate>Thu, 13 Apr 2023 08:45:38 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:2ffff844-d1e0-49e3-99cd-7533f17fe2da</guid><dc:creator>Hung Bui</dc:creator><description>&lt;p&gt;Hi Thomas,&amp;nbsp;&lt;br /&gt;I&amp;#39;m not so sure which filter&amp;nbsp;you are asking about.&amp;nbsp;&lt;br /&gt;But to be able for the sniffer to follow a connection, you would need to select the advertiser. It can only follow one advertiser/connection at a time, so you need to select the advertiser in advance.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: filtering issue using wireshark and nRF52840 sniffer</title><link>https://devzone.nordicsemi.com/thread/419889?ContentTypeID=1</link><pubDate>Wed, 12 Apr 2023 08:30:26 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:ccc063c7-9716-4da9-aa99-07f8edc6178f</guid><dc:creator>Thomas_Thomas</dc:creator><description>&lt;p&gt;Hi Hung,&lt;/p&gt;
&lt;p&gt;Thank you very much it is working, for my understanding, why it doesn&amp;#39;t work with the filter?&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;
&lt;p&gt;Thomas.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: filtering issue using wireshark and nRF52840 sniffer</title><link>https://devzone.nordicsemi.com/thread/419785?ContentTypeID=1</link><pubDate>Tue, 11 Apr 2023 14:44:10 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:08f1ad31-7ebe-40dd-8158-cd6b221b3ebf</guid><dc:creator>Hung Bui</dc:creator><description>&lt;p&gt;Hi Thomas,&amp;nbsp;&lt;br /&gt;I would suggest you to go through Lesson 6 in our Bluetooth Academy here:&amp;nbsp;&lt;a href="https://academy.nordicsemi.com/lessons/lesson-6-bluetooth-le-sniffer/"&gt;https://academy.nordicsemi.com/lessons/lesson-6-bluetooth-le-sniffer/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;It lesson 6 I explained how to use the sniffer to follow a connection. At exercise 2 Step 6 you can find how you can apply a filter.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: filtering issue using wireshark and nRF52840 sniffer</title><link>https://devzone.nordicsemi.com/thread/419589?ContentTypeID=1</link><pubDate>Tue, 11 Apr 2023 09:25:44 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:c4afabb8-0b1c-4e03-9ad2-130e796f6005</guid><dc:creator>Thomas_Thomas</dc:creator><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;I found the right filter for advertisement&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;btle.advertising_address == mac address, it is working fine&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;But I can&amp;#39;t find the right filter for the other exchanges, pairing, data, here it is only for advertising.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Do you have a list of filter commands please? I&amp;#39;m looking for all exchanges based on one MAC, and it looks different from the standard one used with other devices with wireshark&lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>