Display Filters cheat sheet - it will help you create the correct Display Filter in Wireshark.
NB! Since Wireshark v.3.0.0 there are some dissector name changes,
so that you have to use other names in display filters in the following cases:
old "bootp" syntax is replaced by "dhcp", and "ssl" is replaced by "tls".
The syntax "bootp" and "dhcp" still may be used in earlier versions of Wireshark v.3.x.x, but it is now considered deprecated and is colored yellow when creating a display filter.