Are the filters http.host != ""
and http.host
the same? The first one makes the filter text edit turn yellow (suggesting I may get undesirable results) whereas the second passes the syntax check fine. They seem to produce the same output.
How to Use Wireshark HTTP Filter
wireshark
Best Answer
The use of the NOT (!=) operator in Wireshark comes with a caveat, as mentioned in the documentation
It might be that for your specific filter at hand, the current capture are displaying the same results, but it might give you a different result with a different capture
"http.host" means any packet which have HTTP hosts "http.host != "" " means any packet which http.hosts isn't empty.
How will the second one react if you do not have http.host at all (ie: non-http traffic?) you might want to check that