In this section, we'll take a look at how to filter traffic before it's captured with the BPF syntax. So, we'll filter that traffic on the capture interface.
In Wireshark, there are two places to enter a capture filter.
The first one is right on the following main screen. Right in the middle, we have the capture section, and it says, ...using this filter:
Enter a capture filter
. So, we can actually do that on the main screen. Try to enter a capture filter, then it will start capturing with that applied filter. You'll also see that there's a green bookmark icon, as shown in the following screenshot. If you hover over that icon, it says Manage saved bookmarks
. And if we click on that, there's a number of saved bookmarks that are already built into Wireshark. So, if there's a common function that you want to filter on, it may already be in the list:
But you can also go up to the top and click on Manage Capture Filters
. This gives you a list of all of your predefined capture filters...