Filtering network traffic
Wireshark, along with many other packet analysis tools, can take a large capture, filter specific types of traffic, and refine your view to help with analysis. Within Wireshark there are several options you can use to filter traffic:
- Display filters: Used during an active capture or on a pre-captured file
- Capture filters: Applied prior to capture to only display a certain type of traffic
- Expressions: Creates complex filters using logical operators
- Shortcuts: Builds a filter on the fly while analyzing packets
Wireshark has capture and display filters that can be used to refine your view. Each filter is applied during a specific time when analyzing traffic. In the next section, let's explore when the best time is to apply a filter.
Analyzing traffic
While examining traffic, there are four main phases of packet analysis, as discussed in Chapter 2, Using Wireshark. The phases are Gather, Decode, Analyze, and Display, as shown...