How To Use Wireshark Basics
Once the program is launched select the network interface to capture and click on the.
How to use wireshark basics. You can also tell if the packet is part of a conversation. Wireshark does two things. How to use wireshark filters. Capture filters instruct wireshark to only record packets that meet specified criteria. Once you click this button wireshark will start the live capture process.
For example type dns and you ll see only dns packets. The packet list the top pane is a list of all the packets in the capture. These are referred to as display filters. It captures the packets and it presents them to you in a user friendly way. Filters can also be applied to a capture file that has been created so that only certain packets are shown.
That s where wireshark s filters come in. Launch wireshark and begin capturing packets once wireshark is installed launch the program to begin. You can also start wireshark by using the following command line. The most basic way to apply a filter is by typing it into the filter box at the top of the window and clicking apply or pressing enter. So to start a packet capture click on the capture option icon the one with the gears.
When you start typing wireshark will help you autocomplete your filter. Wireshark shows you three different panes for inspecting packet data. A new window will pop up.