How To Use Wireshark Basics
Capture filters instruct wireshark to only record packets that meet specified criteria.
How to use wireshark basics. It captures the packets and it presents them to you in a user friendly way. These are referred to as display filters. You can also start wireshark by using the following command line. That s where wireshark s filters come in. For example type dns and you ll see only dns packets.
Once the program is launched select the network interface to capture and click on the. Wireshark shows you three different panes for inspecting packet data. Wireshark does two things. You can also tell if the packet is part of a conversation. Filters can also be applied to a capture file that has been created so that only certain packets are shown.
Wireshark i eth0 k you can also use the shark fin button on the toolbar as a shortcut to initiate packet capturing. How to use wireshark filters. Obviously without the first you can t do the second. The packet list the top pane is a list of all the packets in the capture. When you click on a packet the other two panes change to show you the details about the selected packet.
So to start a packet capture click on the capture option icon the one with the gears. Launch wireshark and begin capturing packets once wireshark is installed launch the program to begin. When you start typing wireshark will help you autocomplete your filter.