Wireshark capture filter  Updated 2025-07-16
Capture by instead:
sudo wireshark -f http -k
sudo wireshark -f icmp -kFilter by both protocol and host:
sudo wireshark -f 'host 192.168.1.102 and icmp' -kFor application layer capture filtering, the best you can do is by port:There is an 
sudo wireshark -f 'tcp port 80'http filter but only for as a wireshark display filter