Chapter 9. Logging

Note that you must have selected a log class which saves to local file, for encrypted packets, to be able to display them here.

Protocol number

Here, you enter the number(s) of the protocols you want to search for. You can enter a single number (e. g., 5), a range of numbers (e. g., 5-10), a list of numbers and ranges, separated by commas (e. g., 5, 10-20) or nothing at all. If the field is empty, any protocol will match. See appendix C, Lists of Reserved Ports, ICMP Types and Codes, and Internet Protocols, for more information on protocol numbers.

If you want to study all traffic except the one over a certain protocol or protocols, enter the protocol number(s) here and mark the "not" box.

SIP Packet Selection

In this section, you can filter out certain SIP messages based on Call-ID, SIP method, sending or receiving IP address and the content of the To and From headers.

This selection will only have effect on the SIP choices SIP signaling and SIP packets under Show This.

Call-ID

Enter the Call-ID for the event you want to examine. Matching is done only on entire Call- IDs (no substrings).

SIP Methods

Enter the SIP methods that should be displayed, separated by commas. If you enter INVITE, REGISTER, the log will show all INVITE and REGISTER requests, and all responses for these requests. Note that if you want to see ACKs for a call, you have to enter that method as well as INVITE to see the entire call setup.

IP addresses

Enter one or more IP addresses for which you want to see SIP traffic. For the IP addresses entered, all SIP signaling received from and sent to the addresses will be shown.

141