Description of problem: apply the filter "http and ip.addr != 10.16.36.52", the result list still contains packet from or dsted 10.16.36.52. Version-Release number of selected component (if applicable): wireshark-1.0.8-1.el5_3.1 How reproducible: Steps to Reproduce: 1. run wireshark, and start capture on interface 2. filter by ip address 3. Actual results: Expected results: Should not there be any packet with src or dst address is 10.16.36.52 in the result list. Additional info:
http and (ip.addr != 10.16.36.52) is the problematic filter, if I use http and !(ip.addr == 10.16.36.52) then it works well.
This is expected behavior, see http://wiki.wireshark.org/DisplayFilters.