How To Filter And Inspect Packets In Wireshark?

Reading Time: 2 minutes
How To Filter And Inspect Packets In Wireshark?

Here in this blog we will see how to apply Filters and inspect packets. So to apply Filters in Wireshark, we have two ways:

  • In the Display Filter window, at the top of the screen
  • By highlighting a packet and right-clicking on the packet

Wireshark filters use key phrases as follows:

ip.addrSpecifies an IPv4 address
ipv6.addrSpecifies an IPv6 address
srcSource- where the packet came from
dstDestination- where the packet is going

We can also use the following values:

&&Means “and,” as in, “Choose the IP address of 192.168.2.1 and 192.168.2.2”
==Means “equal,” as in “Choose only IP address 192.168.2.1”
!Means “not,” as in, do not show a particular IP address or source port

The Filters which are valid have a green color. If there is any mistake then the box will turn into vivid pink.

Let’s start with an example of how to inspect packets using filters. Suppose we want to see packets that have only an IP address of 18.224.161.65 somewhere inside. We will create the following command line, and put it into the filter window.

ip.addr==18.224.161.65
How To Filter And Inspect Packets In Wireshark?

Alternatively, we can highlight the IP address of a packet and then create a filter for it. Once we select the IP address, right-click, and then select the Apply As Filter Option. We’ll see a menu of additional options. One of those is “Selected”. If we choose “Selected”, then Wireshark will create a filter that shows only packets with that IP address in it.

We can also decide to filter out a specific IP address using the below filter.

!ip.addr==18.224.161.65

Also, we are not limited to IPv4 addresses. If a particular system is active and using an IPv6 address on our network, we can open another Wireshark window and apply the below rule:

ipv6.dst == 2607:f8b0:400a:15::b 

Some Additional Filters Are:

tcp.port==8080Filters packets to show a port of your own choosing – in this case, port 8080
!(ip.src == 162.248.16.53)Shows all packets except those originating from 162.248.16.53
!(ipv6.dst ==
2607:f8b0:400a:15::b
Shows all packets except those going to the IPv6 address of 2607:f8b0:400a:15::b
ip.addr == 192.168.4.1 &&
ip.addr == 192.168.4.2
Shows both 192.168.4.1 and 192.168.4.2
http.requestShows only HTTP requests – useful when troubleshooting or visualizing web traffic

Wireshark is a powerful application. For more information, you can read here.

Written by 

Shubham Saini is a DevOps Engineer who loves to play with DevOps tools, Security methods and is also interested in Ethical Hacking & Cyber Security. He is a gamer also.

Leave a Reply