How To Use Wireshark Basics
Filters can also be applied to a capture file that has been created so that only certain packets are shown.
How to use wireshark basics. That s where wireshark s filters come in. Wireshark does two things. It captures the packets and it presents them to you in a user friendly way. How to use wireshark filters. Wireshark shows you three different panes for inspecting packet data.
Launch wireshark and begin capturing packets once wireshark is installed launch the program to begin. So to start a packet capture click on the capture option icon the one with the gears. A new window will pop up. Once the program is launched select the network interface to capture and click on the. The packet list the top pane is a list of all the packets in the capture.
For example type dns and you ll see only dns packets. When you click on a packet the other two panes change to show you the details about the selected packet. The most basic way to apply a filter is by typing it into the filter box at the top of the window and clicking apply or pressing enter. When you start typing wireshark will help you autocomplete your filter. You can also tell if the packet is part of a conversation.
Wireshark i eth0 k you can also use the shark fin button on the toolbar as a shortcut to initiate packet capturing. Obviously without the first you can t do the second. Once you click this button wireshark will start the live capture process.