Hey guys,

Need some serious help here. one of our clients are complaining that our software is eating their bandwidth. the software updates from a particular URL.

The issue I am having is that it only updates every 4 hours. I would like to only capture HTTP, TCP, and UDP to this particular URL within say 5 hours of running wireshark on the particular windows machine.

As you can imagine without this filter the capture will be too huge for the client to email it to us.

So basically only capture HTTP, TCP and UDP to this particular URL, nothing else.

Can anyone help me out with this. Im tried to get it going within wireshark but cant seem to.

Thanks