Chapter 2. Filtering Our Way in Wireshark

This chapter will talk about different filtering options available in Wireshark, namely, capture and display filters. We will also look at how to create and use different profiles. The following are the topics we will cover in this chapter:

  • An introduction to capture filters
  • Why and how to use capture filters
  • Lab up—capture filters
  • An introduction to display filters
  • Why and how to use display filters
  • Lab up—display filters
  • Colorizing traffic
  • Creating a new Wireshark profile(s)
  • Lab up—profiles

I hope you are ready to start analyzing packets using different filtering options present in Wireshark and to reuse the filters that we previously created in a user-defined profile. I will be guiding you with a technique to ...

Get Mastering Wireshark now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.