From the course: Wireshark: Malware and Forensics

Unlock the full course today

Join today to access over 22,500 courses taught by industry experts or purchase this course individually.

Displaying data using filters

Displaying data using filters - Wireshark Tutorial

From the course: Wireshark: Malware and Forensics

Start my 1-month free trial

Displaying data using filters

- [Instructor] Within Wireshark and most packet capture tools, there are filters to help refine your view. We have display filters, we can apply some filter shortcuts. We can build an expression, and create complex filters. And we can also create a capture filter to capture only a certain type of traffic. I'm at this packet capture here and, as you can see, there's over 3000 packets and a lot of different types of traffic. The display filter, as you can see here, it says, apply a display filter. We use a display filter when we've already captured some packets or are actively capturing packets. When you use the display filter, it's very simple. You simply type whatever it is you would like to display. For example, I would just like TCP traffic. So, I'll type TCP. And then over here, we can either press enter or simply go. Now within that, of course, TCP is the transport layer protocol, and we see a lot of different types…

Contents