Summary

Filtering traffic lets you capture and see only stream of packets you want; there are two types of filters: display filters and capture filters.

Display filters hide the packets; however, capture filters discard the packets that do not meet user defined expression and discarded packets are not passed to the capturing engine.

Capture filters use the BPF syntax, which is an industry standard and is used by several other protocol analyzers.

Find utility is useful and can be accessed from the Edit menu in Wireshark. The Find utility gives various vectors to search a packet(s) and related details.

Coloring preferences comes handy when filtering a set of traffic. Distinguishing packets becomes easy, as the matched packets will be displayed ...

Get Wireshark 2 Quick Start Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.