Expert system usage

In this section, we'll take a look at the expert system in Wireshark, which is a great feature that not many people know about, and it allows you to easily find problems in a packet capture.

You can follow along with the capture that I'll use by downloading the same one off of the Wireshark website. There's a great section of their wiki called SampleCaptures that allows you to download captures that have been submitted by the community:

What we'll do is search for errors, and the first one that comes up is cmp-in-http-with-errors-in-cmp-protocol.pcap.gz. If you download that and extract it, you can open up the pcap file ...

Get Mastering Wireshark 2 now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.