You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Filtering an SMTP conversation between two servers:
818
-
819
-
ip.addr eq <IP1> and ip.addr eq <IP2> and smtp
820
-
821
-
Filtering an HTTP conversation between two servers:
822
-
823
-
ip.addr eq <IP1> and ip.addr eq <IP2> and http
824
-
825
-
Filtering an SMTP Conversation with TLS between two servers:
826
-
827
-
ip.addr eq <IP1> and ip.addr eq <IP2> and ssl
828
-
829
-
Filtering outgoing packets from ona particular IP:
830
-
831
-
ip.src eq <IP>
832
-
833
-
Filtering incoming packets from one particular IP:
834
-
835
-
ip.dst eq <IP>
836
-
837
-
Filtering the number of SMTP sessions:
838
-
839
-
smtp.req.command eq QUIT
840
-
841
-
Filtering the number of transmited mails:
842
-
843
-
smtp.req.command eq MAIL
844
-
845
-
Filtering the number of recipients in an SMTP conversation:
846
-
847
-
smtp.req.command eq RCPT
848
-
849
-
Filtering a specific recipient mailbox:
850
-
851
-
smtp.req.command eq RCPT and smtp.req.parameter contains “[email protected]”
852
-
853
-
Filtering a specific sender mailbox:
854
-
855
-
smtp.req.command eq MAIL and smtp.req.parameter conatains “[email protected]”
856
-
857
-
Filtering SMTP errors:
858
-
859
-
If you know the error code then use this filter:
860
-
861
-
smtp.response.code eq <ERROR_CODE>
862
-
863
-
for example: smtp.response.code eq 421
864
-
865
-
If you don’t know it, or if you want to list all SMTP errors in the SMTP sessions, then you must first exclude all the valid codes (2XX) until you end up only with 4XX or 5XX codes.
866
-
867
-
not smtp.response.code eq 220 and not smtp.response.code eq 221 and not smtp.response.code eq 250 and not smtp.response.code eq 354 and smtp.response.code
868
-
869
-
When you execute this filter you will end up only with 4XX and/or 5XX error codes so you will see all SMTP errors withing your capture. If it ends up blank, it means that no SMTP errors were found in that specific capture.
0 commit comments