Hello Florent,
Your understanding of how filtering should work is probably correct - there is certainly something odd about the output.
In addition to the mismatch between the filter set and the packets captured, the oddities include:
- Apparence values (should be 0)
- Filtre values (should be 1, given the "pktmon filter list" output)
- The second and third capture reports seem to be two appearances (195 and 196) of the same packet (identical PktGroupId and PktNumber values), which is not itself unusual, but with different OriginalSize values (which is unexpected).
This is not normal behaviour - I can't reproduce it. Is there anything unusual (e.g. installed network drivers (perhaps Wireshark npmon or similar)) about the system that you can tell us? Can you reproduce the problem on other systems?
Gary