data:image/s3,"s3://crabby-images/710fb/710fb16b42eed188d667ff18a9f2af2343c8eb06" alt="Wireshark usb in to usb out"
data:image/s3,"s3://crabby-images/5eb05/5eb05c701e0db9d165ffa63e0d750ad26ae1ef27" alt="wireshark usb in to usb out wireshark usb in to usb out"
data:image/s3,"s3://crabby-images/60b1e/60b1e37f8b1125af2d30da939560d239432ba7be" alt="wireshark usb in to usb out wireshark usb in to usb out"
In your case with a single root hub, m will always be 1.
data:image/s3,"s3://crabby-images/9e2c8/9e2c89aa345cd475fa819b531a23d48fa6870645" alt="wireshark usb in to usb out wireshark usb in to usb out"
If you unplug a device and plug it again to the same physical port, it will keep the m but get a new n. So in your case, as tsharks returns just a single USB interface to capture at, there is just a single root hub in the PC.ĭuring USB enumeration phase, each USB device detected is assigned an ID like m.n, where m is the root hub number and n is the order number of the device to be identified. This number translates into a capturing interface name if you use the extcap API to control the USBPcap, which is what you seem to be doing as you've provided a tshark. Simply put, there is no capture filter available for usb capturing, except the root hub (or "bus") number.
data:image/s3,"s3://crabby-images/710fb/710fb16b42eed188d667ff18a9f2af2343c8eb06" alt="Wireshark usb in to usb out"