Wireshark is the world's most used network protocol analyzer. It is free and open source. It is mostly used for network troubleshooting and analysis. In this recipe, you will learn some basic things about Wireshark and how we can use it to analyze the network traffic in order to find out what information is actually flowing through our network.
The following steps demonstrate the use of Wireshark:
- Wireshark can be opened using the
Wireshark
command:
- We select the interface we want to capture traffic on:
- Then, we click on
Start
. Display filters are used to see general packet filtering while capturing the network traffic. For example:tcp.port eq 80
as shown in the following screenshot:
- Applying the filter will show only the traffic on port
80
. If we want to view requests only from a particular IP, we select the request and right-click on it.
- Then, we navigate to
Apply as Filter
...