igforum.bio / how-to-use-wireshark-a-complete-tutorial - 115214
B
%Start How to Use Wireshark: A Complete Tutorial GA
S
REGULAR Menu Lifewire Tech for Humans Newsletter! Search Close GO Internet, Networking, & Security &gt; Home Networking 504 504 people found this article helpful <h1>
How to Use Wireshark: A Complete Tutorial</h1>
<h2>
Capture and view the data traveling on your network with Wireshark</h2> By Scott Orgera Scott Orgera Writer Scott Orgera is a former Lifewire writer covering tech since 2007.
%Start How to Use Wireshark: A Complete Tutorial GA S REGULAR Menu Lifewire Tech for Humans Newsletter! Search Close GO Internet, Networking, & Security > Home Networking 504 504 people found this article helpful

How to Use Wireshark: A Complete Tutorial

Capture and view the data traveling on your network with Wireshark

By Scott Orgera Scott Orgera Writer Scott Orgera is a former Lifewire writer covering tech since 2007.
thumb_up Like (24)
comment Reply (3)
share Share
visibility 440 views
thumb_up 24 likes
comment 3 replies
S
Sophia Chen 4 minutes ago
He has 25+ years' experience as a programmer and QA leader, and holds several Microsoft cert...
V
Victoria Lopez 4 minutes ago
Because it can drill down and read the contents of each packet, it's used to troubleshoot network pr...
A
He has 25&#43; years&#39; experience as a programmer and QA leader, and holds several Microsoft certifications including MCSE, MCP&#43;I, and MOUS. He is also A&#43; certified. lifewire's editorial guidelines Updated on July 8, 2020 Tweet Share Email Tweet Share Email Home Networking The Wireless Connection Routers & Firewalls Network Hubs ISP Broadband Ethernet Installing & Upgrading Wi-Fi & Wireless <h3>
What to Know</h3> Wireshark is an open-source application that captures and displays data traveling back and forth on a network.
He has 25+ years' experience as a programmer and QA leader, and holds several Microsoft certifications including MCSE, MCP+I, and MOUS. He is also A+ certified. lifewire's editorial guidelines Updated on July 8, 2020 Tweet Share Email Tweet Share Email Home Networking The Wireless Connection Routers & Firewalls Network Hubs ISP Broadband Ethernet Installing & Upgrading Wi-Fi & Wireless

What to Know

Wireshark is an open-source application that captures and displays data traveling back and forth on a network.
thumb_up Like (15)
comment Reply (2)
thumb_up 15 likes
comment 2 replies
S
Scarlett Brown 2 minutes ago
Because it can drill down and read the contents of each packet, it's used to troubleshoot network pr...
D
Daniel Kumar 2 minutes ago

What Is Wireshark

Originally known as Ethereal, Wireshark displays data from hundreds of...
D
Because it can drill down and read the contents of each packet, it's used to troubleshoot network problems and test software. Instructions in this article apply to Wireshark 3.0.3 for Windows and Mac.
Because it can drill down and read the contents of each packet, it's used to troubleshoot network problems and test software. Instructions in this article apply to Wireshark 3.0.3 for Windows and Mac.
thumb_up Like (10)
comment Reply (2)
thumb_up 10 likes
comment 2 replies
M
Madison Singh 6 minutes ago

What Is Wireshark

Originally known as Ethereal, Wireshark displays data from hundreds of...
O
Oliver Taylor 2 minutes ago
Wireshark supports dozens of capture/trace file formats, including CAP and ERF. Integrated decryptio...
E
<h2> What Is Wireshark  </h2> Originally known as Ethereal, Wireshark displays data from hundreds of different protocols on all major network types. Data packets can be viewed in real-time or analyzed offline.

What Is Wireshark

Originally known as Ethereal, Wireshark displays data from hundreds of different protocols on all major network types. Data packets can be viewed in real-time or analyzed offline.
thumb_up Like (5)
comment Reply (0)
thumb_up 5 likes
S
Wireshark supports dozens of capture/trace file formats, including CAP and ERF. Integrated decryption tools display the encrypted packets for several common protocols, including WEP and WPA/WPA2.
Wireshark supports dozens of capture/trace file formats, including CAP and ERF. Integrated decryption tools display the encrypted packets for several common protocols, including WEP and WPA/WPA2.
thumb_up Like (22)
comment Reply (2)
thumb_up 22 likes
comment 2 replies
Z
Zoe Mueller 18 minutes ago

How to Download and Install Wireshark

Wireshark can be downloaded at no cost from the Wir...
E
Emma Wilson 1 minutes ago
Unless you're an advanced user, download the stable version. During the Windows setup process, choos...
E
<h2> How to Download and Install Wireshark </h2> Wireshark can be downloaded at no cost from the Wireshark Foundation website for both macOS and Windows. You'll see the latest stable release and the current developmental release.

How to Download and Install Wireshark

Wireshark can be downloaded at no cost from the Wireshark Foundation website for both macOS and Windows. You'll see the latest stable release and the current developmental release.
thumb_up Like (24)
comment Reply (3)
thumb_up 24 likes
comment 3 replies
J
Joseph Kim 13 minutes ago
Unless you're an advanced user, download the stable version. During the Windows setup process, choos...
G
Grace Liu 7 minutes ago
In Windows 10, search for Wireshark and select Run as administrator. In macOS, right-click the app i...
H
Unless you're an advanced user, download the stable version. During the Windows setup process, choose to install WinPcap or Npcap if prompted as these include libraries required for live data capture. You must be logged in to the device as an administrator to use Wireshark.
Unless you're an advanced user, download the stable version. During the Windows setup process, choose to install WinPcap or Npcap if prompted as these include libraries required for live data capture. You must be logged in to the device as an administrator to use Wireshark.
thumb_up Like (27)
comment Reply (3)
thumb_up 27 likes
comment 3 replies
S
Sophie Martin 8 minutes ago
In Windows 10, search for Wireshark and select Run as administrator. In macOS, right-click the app i...
E
Elijah Patel 15 minutes ago
In the Sharing & Permissions settings, give the admin Read & Write privileges. The applicati...
E
In Windows 10, search for Wireshark and select Run as administrator. In macOS, right-click the app icon and select Get Info.
In Windows 10, search for Wireshark and select Run as administrator. In macOS, right-click the app icon and select Get Info.
thumb_up Like (41)
comment Reply (3)
thumb_up 41 likes
comment 3 replies
I
Isabella Johnson 10 minutes ago
In the Sharing & Permissions settings, give the admin Read & Write privileges. The applicati...
E
Elijah Patel 19 minutes ago
The binaries required for these operating systems can be found toward the bottom of the Wireshark do...
L
In the Sharing &amp; Permissions settings, give the admin Read &amp; Write privileges. The application is also available for Linux and other UNIX-like platforms including Red Hat, Solaris, and FreeBSD.
In the Sharing & Permissions settings, give the admin Read & Write privileges. The application is also available for Linux and other UNIX-like platforms including Red Hat, Solaris, and FreeBSD.
thumb_up Like (0)
comment Reply (1)
thumb_up 0 likes
comment 1 replies
J
Jack Thompson 11 minutes ago
The binaries required for these operating systems can be found toward the bottom of the Wireshark do...
D
The binaries required for these operating systems can be found toward the bottom of the Wireshark download page under the Third-Party Packages section. You can also download Wireshark's source code from this page.
The binaries required for these operating systems can be found toward the bottom of the Wireshark download page under the Third-Party Packages section. You can also download Wireshark's source code from this page.
thumb_up Like (4)
comment Reply (2)
thumb_up 4 likes
comment 2 replies
C
Charlotte Lee 6 minutes ago

How to Capture Data Packets With Wireshark

When you launch Wireshark, a welcome screen li...
E
Ethan Thomas 8 minutes ago
To select multiple networks, hold the Shift key as you make your selection. In the Wireshark Capture...
E
<h2> How to Capture Data Packets With Wireshark </h2> When you launch Wireshark, a welcome screen lists the available network connections on your current device. Displayed to the right of each is an EKG-style line graph that represents live traffic on that network. To begin capturing packets with Wireshark: Select one or more of networks, go to the menu bar, then select Capture.

How to Capture Data Packets With Wireshark

When you launch Wireshark, a welcome screen lists the available network connections on your current device. Displayed to the right of each is an EKG-style line graph that represents live traffic on that network. To begin capturing packets with Wireshark: Select one or more of networks, go to the menu bar, then select Capture.
thumb_up Like (19)
comment Reply (3)
thumb_up 19 likes
comment 3 replies
D
Dylan Patel 12 minutes ago
To select multiple networks, hold the Shift key as you make your selection. In the Wireshark Capture...
O
Oliver Taylor 36 minutes ago
There are other ways to initiate packet capturing. Select the shark fin on the left side of the Wire...
S
To select multiple networks, hold the Shift key as you make your selection. In the Wireshark Capture Interfaces window, select Start.
To select multiple networks, hold the Shift key as you make your selection. In the Wireshark Capture Interfaces window, select Start.
thumb_up Like (2)
comment Reply (0)
thumb_up 2 likes
O
There are other ways to initiate packet capturing. Select the shark fin on the left side of the Wireshark toolbar, press ​Ctrl&#43;E, or double-click the network.
There are other ways to initiate packet capturing. Select the shark fin on the left side of the Wireshark toolbar, press ​Ctrl+E, or double-click the network.
thumb_up Like (16)
comment Reply (2)
thumb_up 16 likes
comment 2 replies
J
Jack Thompson 2 minutes ago
Select File > Save As or choose an Export option to record the capture. To stop capturing, press ...
J
Jack Thompson 41 minutes ago

How to View and Analyze Packet Contents

The captured data interface contains three main s...
L
Select File &gt; Save As or choose an Export option to record the capture. To stop capturing, press Ctrl&#43;E. Or, go to the Wireshark toolbar and select the red Stop button that&#39;s located next to the shark fin.
Select File > Save As or choose an Export option to record the capture. To stop capturing, press Ctrl+E. Or, go to the Wireshark toolbar and select the red Stop button that's located next to the shark fin.
thumb_up Like (1)
comment Reply (0)
thumb_up 1 likes
E
<h2> How to View and Analyze Packet Contents </h2> The captured data interface contains three main sections: The packet list pane (the top section)The packet details pane (the middle section)The packet bytes pane (the bottom section) 
 <h3> Packet List </h3> The packet list pane, located at the top of the window, shows all packets found in the active capture file. Each packet has its own row and corresponding number assigned to it, along with each of these data points: No: This field indicates which packets are part of the same conversation. It remains blank until you select a packet.Time: The timestamp of when the packet was captured is displayed in this column.

How to View and Analyze Packet Contents

The captured data interface contains three main sections: The packet list pane (the top section)The packet details pane (the middle section)The packet bytes pane (the bottom section)

Packet List

The packet list pane, located at the top of the window, shows all packets found in the active capture file. Each packet has its own row and corresponding number assigned to it, along with each of these data points: No: This field indicates which packets are part of the same conversation. It remains blank until you select a packet.Time: The timestamp of when the packet was captured is displayed in this column.
thumb_up Like (8)
comment Reply (2)
thumb_up 8 likes
comment 2 replies
J
Julia Zhang 16 minutes ago
The default format is the number of seconds or partial seconds since this specific capture file was ...
E
Ella Rodriguez 13 minutes ago
To change the time format to something more useful (such as the actual time of day), select View >...
L
The default format is the number of seconds or partial seconds since this specific capture file was first created.Source: This column contains the address (IP or other) where the packet originated.Destination: This column contains the address that the packet is being sent to.Protocol: The packet&#39;s protocol name, such as TCP, can be found in this column.Length: The packet length, in bytes, is displayed in this column.Info: Additional details about the packet are presented here. The contents of this column can vary greatly depending on packet contents.
The default format is the number of seconds or partial seconds since this specific capture file was first created.Source: This column contains the address (IP or other) where the packet originated.Destination: This column contains the address that the packet is being sent to.Protocol: The packet's protocol name, such as TCP, can be found in this column.Length: The packet length, in bytes, is displayed in this column.Info: Additional details about the packet are presented here. The contents of this column can vary greatly depending on packet contents.
thumb_up Like (19)
comment Reply (0)
thumb_up 19 likes
J
To change the time format to something more useful (such as the actual time of day), select View &gt; Time Display Format. When a packet is selected in the top pane, you may notice one or more symbols appear in the No. column.
To change the time format to something more useful (such as the actual time of day), select View > Time Display Format. When a packet is selected in the top pane, you may notice one or more symbols appear in the No. column.
thumb_up Like (6)
comment Reply (0)
thumb_up 6 likes
W
Open or closed brackets and a straight horizontal line indicate whether a packet or group of packets are part of the same back-and-forth conversation on the network. A broken horizontal line signifies that a packet is not part of the conversation. <h3> Packet Details </h3> The details pane, found in the middle, presents the protocols and protocol fields of the selected packet in a collapsible format.
Open or closed brackets and a straight horizontal line indicate whether a packet or group of packets are part of the same back-and-forth conversation on the network. A broken horizontal line signifies that a packet is not part of the conversation.

Packet Details

The details pane, found in the middle, presents the protocols and protocol fields of the selected packet in a collapsible format.
thumb_up Like (11)
comment Reply (3)
thumb_up 11 likes
comment 3 replies
S
Sofia Garcia 17 minutes ago
In addition to expanding each selection, you can apply individual Wireshark filters based on specifi...
I
Isaac Schmidt 16 minutes ago
Selecting a specific portion of this data automatically highlights its corresponding section in the ...
D
In addition to expanding each selection, you can apply individual Wireshark filters based on specific details and follow streams of data based on protocol type by right-clicking the desired item. <h3> Packet Bytes </h3> At the bottom is the packet bytes pane, which displays the raw data of the selected packet in a hexadecimal view. This hex dump contains 16 hexadecimal bytes and 16 ASCII bytes alongside the data offset.
In addition to expanding each selection, you can apply individual Wireshark filters based on specific details and follow streams of data based on protocol type by right-clicking the desired item.

Packet Bytes

At the bottom is the packet bytes pane, which displays the raw data of the selected packet in a hexadecimal view. This hex dump contains 16 hexadecimal bytes and 16 ASCII bytes alongside the data offset.
thumb_up Like (48)
comment Reply (1)
thumb_up 48 likes
comment 1 replies
S
Sofia Garcia 60 minutes ago
Selecting a specific portion of this data automatically highlights its corresponding section in the ...
L
Selecting a specific portion of this data automatically highlights its corresponding section in the packet details pane and vice versa. Any bytes that cannot be printed are represented by a period.
Selecting a specific portion of this data automatically highlights its corresponding section in the packet details pane and vice versa. Any bytes that cannot be printed are represented by a period.
thumb_up Like (5)
comment Reply (2)
thumb_up 5 likes
comment 2 replies
E
Elijah Patel 11 minutes ago
To display this data in bit format as opposed to hexadecimal, right-click anywhere within the pane a...
H
Henry Schmidt 20 minutes ago
These are referred to as display filters. Wireshark provides a large number of predefined filters by...
L
To display this data in bit format as opposed to hexadecimal, right-click anywhere within the pane and select as bits. <h2> How to Use Wireshark Filters </h2> Capture filters instruct Wireshark to only record packets that meet specified criteria. Filters can also be applied to a capture file that has been created so that only certain packets are shown.
To display this data in bit format as opposed to hexadecimal, right-click anywhere within the pane and select as bits.

How to Use Wireshark Filters

Capture filters instruct Wireshark to only record packets that meet specified criteria. Filters can also be applied to a capture file that has been created so that only certain packets are shown.
thumb_up Like (41)
comment Reply (0)
thumb_up 41 likes
L
These are referred to as display filters. Wireshark provides a large number of predefined filters by default.
These are referred to as display filters. Wireshark provides a large number of predefined filters by default.
thumb_up Like (11)
comment Reply (1)
thumb_up 11 likes
comment 1 replies
A
Amelia Singh 21 minutes ago
To use one of these existing filters, enter its name in the Apply a display filter entry field locat...
E
To use one of these existing filters, enter its name in the Apply a display filter entry field located below the Wireshark toolbar or in the Enter a capture filter field located in the center of the welcome screen. For example, if you want to display TCP packets, type tcp. The Wireshark autocomplete feature shows suggested names as you begin typing, making it easier to find the correct moniker for the filter you&#39;re seeking.
To use one of these existing filters, enter its name in the Apply a display filter entry field located below the Wireshark toolbar or in the Enter a capture filter field located in the center of the welcome screen. For example, if you want to display TCP packets, type tcp. The Wireshark autocomplete feature shows suggested names as you begin typing, making it easier to find the correct moniker for the filter you're seeking.
thumb_up Like (31)
comment Reply (2)
thumb_up 31 likes
comment 2 replies
N
Natalie Lopez 49 minutes ago
Another way to choose a filter is to select the bookmark on the left side of the entry field. Choose...
E
Emma Wilson 9 minutes ago
Capture filters are applied as soon as you begin recording network traffic. To apply a display filte...
M
Another way to choose a filter is to select the bookmark on the left side of the entry field. Choose Manage Filter Expressions or Manage Display Filters to add, remove, or edit filters. You can also access previously used filters by selecting the down arrow on the right side of the entry field to display a history drop-down list.
Another way to choose a filter is to select the bookmark on the left side of the entry field. Choose Manage Filter Expressions or Manage Display Filters to add, remove, or edit filters. You can also access previously used filters by selecting the down arrow on the right side of the entry field to display a history drop-down list.
thumb_up Like (50)
comment Reply (2)
thumb_up 50 likes
comment 2 replies
T
Thomas Anderson 15 minutes ago
Capture filters are applied as soon as you begin recording network traffic. To apply a display filte...
H
Henry Schmidt 31 minutes ago
This quickly locates certain packets within a saved set by their row color in the packet list pane. ...
D
Capture filters are applied as soon as you begin recording network traffic. To apply a display filter, select the right arrow on the right side of the entry field. <h2> Wireshark Color Rules </h2> While Wireshark&#39;s capture and display filters limit which packets are recorded or shown on the screen, its colorization function takes things a step further: It can distinguish between different packet types based on their individual hue.
Capture filters are applied as soon as you begin recording network traffic. To apply a display filter, select the right arrow on the right side of the entry field.

Wireshark Color Rules

While Wireshark's capture and display filters limit which packets are recorded or shown on the screen, its colorization function takes things a step further: It can distinguish between different packet types based on their individual hue.
thumb_up Like (43)
comment Reply (3)
thumb_up 43 likes
comment 3 replies
D
David Cohen 112 minutes ago
This quickly locates certain packets within a saved set by their row color in the packet list pane. ...
O
Oliver Taylor 94 minutes ago
Select View > Coloring Rules for an overview of what each color means. You can also add your own ...
L
This quickly locates certain packets within a saved set by their row color in the packet list pane. Wireshark comes with about 20 default coloring rules, each can be edited, disabled, or deleted.
This quickly locates certain packets within a saved set by their row color in the packet list pane. Wireshark comes with about 20 default coloring rules, each can be edited, disabled, or deleted.
thumb_up Like (1)
comment Reply (1)
thumb_up 1 likes
comment 1 replies
A
Amelia Singh 15 minutes ago
Select View > Coloring Rules for an overview of what each color means. You can also add your own ...
G
Select View &gt; Coloring Rules for an overview of what each color means. You can also add your own color-based filters.
Select View > Coloring Rules for an overview of what each color means. You can also add your own color-based filters.
thumb_up Like (31)
comment Reply (1)
thumb_up 31 likes
comment 1 replies
J
Jack Thompson 78 minutes ago
Select View > Colorize Packet List to toggle packet colorization on and off.

Statistics in W...

L
Select View &gt; Colorize Packet List to toggle packet colorization on and off. <h2> Statistics in Wireshark </h2> Other useful metrics are available through the Statistics drop-down menu.
Select View > Colorize Packet List to toggle packet colorization on and off.

Statistics in Wireshark

Other useful metrics are available through the Statistics drop-down menu.
thumb_up Like (15)
comment Reply (2)
thumb_up 15 likes
comment 2 replies
L
Lucas Martinez 16 minutes ago
These include size and timing information about the capture file, along with dozens of charts and gr...
H
Hannah Kim 7 minutes ago

Wireshark Advanced Features

Wireshark also supports advanced features, including the abil...
J
These include size and timing information about the capture file, along with dozens of charts and graphs ranging in topic from packet conversation breakdowns to load distribution of HTTP requests. Display filters can be applied to many of these statistics via their interfaces, and the results can be exported to common file formats, including CSV, XML, and TXT.
These include size and timing information about the capture file, along with dozens of charts and graphs ranging in topic from packet conversation breakdowns to load distribution of HTTP requests. Display filters can be applied to many of these statistics via their interfaces, and the results can be exported to common file formats, including CSV, XML, and TXT.
thumb_up Like (40)
comment Reply (3)
thumb_up 40 likes
comment 3 replies
E
Elijah Patel 11 minutes ago

Wireshark Advanced Features

Wireshark also supports advanced features, including the abil...
O
Oliver Taylor 29 minutes ago
Thanks for letting us know! Get the Latest Tech News Delivered Every Day Subscribe Tell us why! Othe...
I
<h2> Wireshark Advanced Features </h2> Wireshark also supports advanced features, including the ability to write protocol dissectors in the Lua programming language. Was this page helpful?

Wireshark Advanced Features

Wireshark also supports advanced features, including the ability to write protocol dissectors in the Lua programming language. Was this page helpful?
thumb_up Like (20)
comment Reply (1)
thumb_up 20 likes
comment 1 replies
C
Christopher Lee 37 minutes ago
Thanks for letting us know! Get the Latest Tech News Delivered Every Day Subscribe Tell us why! Othe...
C
Thanks for letting us know! Get the Latest Tech News Delivered Every Day
Subscribe Tell us why! Other Not enough details Hard to understand Submit More from Lifewire How to Monitor Network Traffic Task Manager (What It Is & How to Use It) CAP File (What It Is and How to Open One) How to Use Microsoft Word How to Use the Netstat Command on Mac How to Use Night Light in Windows 10 How to Use the Netstat Command TCP vs.
Thanks for letting us know! Get the Latest Tech News Delivered Every Day Subscribe Tell us why! Other Not enough details Hard to understand Submit More from Lifewire How to Monitor Network Traffic Task Manager (What It Is & How to Use It) CAP File (What It Is and How to Open One) How to Use Microsoft Word How to Use the Netstat Command on Mac How to Use Night Light in Windows 10 How to Use the Netstat Command TCP vs.
thumb_up Like (28)
comment Reply (3)
thumb_up 28 likes
comment 3 replies
L
Liam Wilson 1 minutes ago
UDP How to Highlight and Find Duplicates in Google Sheets How to Use the iPhone Camera Network MTU v...
V
Victoria Lopez 47 minutes ago
Cookies Settings Accept All Cookies...
J
UDP How to Highlight and Find Duplicates in Google Sheets How to Use the iPhone Camera Network MTU vs. Maximum TCP How to Freeze Column and Row Headings in Excel How to Use the Round Function in Excel How Web Browsers and Web Servers Communicate How to Send iMessages With iPhone Text Effects How to Set Up PPPoE Internet Access Newsletter Sign Up Newsletter Sign Up Newsletter Sign Up Newsletter Sign Up Newsletter Sign Up By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts.
UDP How to Highlight and Find Duplicates in Google Sheets How to Use the iPhone Camera Network MTU vs. Maximum TCP How to Freeze Column and Row Headings in Excel How to Use the Round Function in Excel How Web Browsers and Web Servers Communicate How to Send iMessages With iPhone Text Effects How to Set Up PPPoE Internet Access Newsletter Sign Up Newsletter Sign Up Newsletter Sign Up Newsletter Sign Up Newsletter Sign Up By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts.
thumb_up Like (3)
comment Reply (0)
thumb_up 3 likes
L
Cookies Settings Accept All Cookies
Cookies Settings Accept All Cookies
thumb_up Like (6)
comment Reply (3)
thumb_up 6 likes
comment 3 replies
S
Scarlett Brown 79 minutes ago
How to Use Wireshark: A Complete Tutorial GA S REGULAR Menu Lifewire Tech for Humans Newsletter! Sea...
S
Sebastian Silva 72 minutes ago
He has 25+ years' experience as a programmer and QA leader, and holds several Microsoft cert...

Write a Reply