Welcome to my second part of “Introduction to Wireshark”
I am happy to see you back here.
In the first part we started to get a first overview about Wireshark and how to start capturing traffic.
Following article will show some of the most needed capture and display filter.
In addition I will show you some basic statistics to get a first overview about your tcpdump.
Time to read:
- 5 min
- Beginner’s Level
- Filter Syntax
- Statistics: Capture File Properties
- Statistics: Protocol Hierarchy & Conversations
Filter Syntax (Updated: 21.12.2017)
The table below shows the filters you need to set for your specific goals.
It is very cool to be able to use the “or / and” operators also in the filter section.
|Description||Capture Filter||Display Filter|
|Filter for 1 IP Address||host 220.127.116.11||ip.addr==18.104.22.168|
|Filter for more than 1 IP Address||host 22.214.171.124 or host 126.96.36.199||ip.addr==188.8.131.52 or ip.addr==184.108.40.206|
|Filter for 1 TCP Port||tcp port 443||tcp.port==443|
|Filter for 1 IP Address and 1 TCP Port||host 220.127.116.11 and tcp port 443||ip.addr==18.104.22.168 and tcp.port==443|
|Filter to show retransmissions||tcp.analysis.retransmission|
Statistics: Capture File Properties
The first step I usually do when I open a tcpdump in Wireshark is to open the “Capture File Properties”.
It will show details like:
- Start + End Time of the Trace.
- Interface statistics.
- Statistics (Number of Packets, Average pps, Average packet size, Bytes, Average bytes/s, Average bits/s).
To open it click on the “Statistic” tab and select the first choice “Capture File Properties”.
Statistics: Protocol Hierarchy & Conversations
An important step is to get an overview about the captured protocols and TCP conversations.
The “Protocol Hierarchy” gives you a statistic which shows how many packets / bytes / bits are sent by Protocol.
To open it click on the “Statistic” tab and select “Protocol Hierarchy”.
The “Conversations” statistic give you the same information by conversation for the “Ethernet, IPv4, IPv4, TCP, UDP” layer.
To open it click on the “Statistic” tab and select “Conversations”.
My feeling is that the topics covered in this article should give a first introduction to Wireshark filters and statistics. You can already see how powerful Wireshark is.
In my next articles I will cover more about the analysis of specific use cases.