In this section, we'll take a look at how to display useful statistics in Wireshark and some issues you could troubleshoot utilizing that statistical information.
In order to access the statistics in Wireshark, click on Statistics
and go to Resolved Addresses
:
The Resolved Addresses
window will give you a list at the top of all of the IP addresses and DNS names that were resolved in your packet capture. This way, you can get an idea of all the different resources that were accessed in your packet capture:
Next we'll look at protocol hierarchy. You need to click on Statistics
and go to Protocol Hierarchy
:
It will give you a breakdown based on the percentages of the packets of the most popular protocols that it saw:
As you can see at the beginning, everything that came in was a Frame
. Everything that came in that Frame
was an Ethernet
frame. And then within that, we have a breakdown of what's within Ethernet
. So we have some Internet Protocol...