Professional Documents
Culture Documents
https://www.varonis.com/blog/how-to-use-wireshark 7/21
24/6/22, 14:57 How to Use Wireshark: Comprehensive Tutorial + Tips
https://www.varonis.com/blog/how-to-use-wireshark 8/21
24/6/22, 14:57 How to Use Wireshark: Comprehensive Tutorial + Tips
Ubuntu
Kali Linux
https://www.varonis.com/blog/how-to-use-wireshark 9/21
24/6/22, 14:57 How to Use Wireshark: Comprehensive Tutorial + Tips
network traffic.
When you open Wireshark, you see a screen that shows you
a list of all of the network connections you can monitor. You
also have a capture filter field, so you only capture the
network traffic you want to see.
https://www.varonis.com/blog/how-to-use-wireshark 10/21
24/6/22, 14:57 How to Use Wireshark: Comprehensive Tutorial + Tips
During the capture, Wireshark will show you the packets that
it captures in real-time.
https://www.varonis.com/blog/how-to-use-wireshark 11/21
24/6/22, 14:57 How to Use Wireshark: Comprehensive Tutorial + Tips
Once you have captured all the packets you need, you use
the same buttons or menu options to stop the capture.
Time: This column shows you how long after you started
the capture that this packet got captured. You can
change this value in the Settings menu if you need
something different displayed.
Wireshark Filters
One of the best features of Wireshark is the Wireshark
Capture Filters and Wireshark Display Filters. Filters allow
you to view the capture the way you need to see it so you
can troubleshoot the issues at hand. Here are several filters
to get you started.
https://www.varonis.com/blog/how-to-use-wireshark 13/21
24/6/22, 14:57 How to Use Wireshark: Comprehensive Tutorial + Tips
port not 53 and not arp: capture all traffic except DNS and
ARP traffic
tcp.port eq 25: This filter will show you all traffic on port 25,
which is usually SMTP traffic.
https://www.varonis.com/blog/how-to-use-wireshark 14/21
24/6/22, 14:57 How to Use Wireshark: Comprehensive Tutorial + Tips
icmp: This filter will show you only ICMP traffic in the
capture, most likely they are pings.
ls_ads.opnum==0x09
https://www.varonis.com/blog/how-to-use-wireshark 15/21
24/6/22, 14:57 How to Use Wireshark: Comprehensive Tutorial + Tips
Wireshark Commands
https://www.varonis.com/blog/how-to-use-wireshark 16/21
24/6/22, 14:57 How to Use Wireshark: Comprehensive Tutorial + Tips
https://www.varonis.com/blog/how-to-use-wireshark 17/21
24/6/22, 14:57 How to Use Wireshark: Comprehensive Tutorial + Tips
Additional Wireshark
Resources and Tutorials
There are many tutorials and videos around that you show
you how to use Wireshark for specific purposes. You should
start on the main Wireshark website and move forward from
https://www.varonis.com/blog/how-to-use-wireshark 18/21
24/6/22, 14:57 How to Use Wireshark: Comprehensive Tutorial + Tips
Jeff Petters
Keep reading
https://www.varonis.com/blog/how-to-use-wireshark 20/21