Tips to be better at wireshark

Bird222

Diamond Member
Jun 7, 2004
3,641
132
106
Can you guys give some tips so I can be more proficient at using wireshark. I can scroll through and find packets but that isn't very good. How can I use filters? How can I see a stream from start to finish between two IPs or two interfaces? Or all the udp traffic between two IPs? Or capture only a certain protocol between IPs, for instance ARP? Stuff like that. Help.
 
Last edited:

Gryz

Golden Member
Aug 28, 2010
1,551
204
106
Last edited:

unokitty

Diamond Member
Jan 5, 2012
3,346
1
0
Can you guys give some tips so I can be more proficient at using wireshark. I can scroll through and find packets but that isn't very good. How can I use filters? How can I see a stream from start to finish between two IPs or two interfaces? Or all the udp traffic between two IPs? Or capture only a certain protocol between IPs, for instance ARP? Stuff like that. Help.


Couple of things:

One
Watch the Introduction to Wireshark Video that is narrated by Gearld Coombs.

Two
Watch the other videos available on Wireshark.org

Three
Watch Laura Chappell's Youtube videos. Better yet, if you can, attend one of her Wireshark seminars...

Then, practice, practice, practice... There is no substitute for time on task!

Best of luck,
Uno