Enhancing the interface

In Wireshark, there are several ways to alter and enhance the interface, such as how we view the toolbars and which panels we would like to be visible. We'll start at the top with the toolbars.

The toolbar section represents a grouping where similar items are combined in many menus. Once in this section, you will see a list of the three available toolbars that are currently available, as shown here:

The View menu—toolbars

 If you see a checkmark as shown in the preceding screenshot, that indicates the toolbar is visible. The toolbars are explained as follows:

  • Main Toolbar: This holds all of the commonly accessed icons:

Main Toolbar
  • Filter Toolbar: This is where you will find the display filter.
  • Status Bar: This is found at the bottom of the Wireshark screen. The Status Bar tells how many packets are captured and how many are displayed, what profile is applied, and the name of the file.
  • Full Screen: This is used when we want Wireshark to go full screen, which will fill the current window.

Once you get used to the toolbars, you will see they provide a handy way to help you to navigate the interface. Now, let's take a look at the next grouping, which is the panel view, so you can modify what is visible on the screen. A checkmark indicates the panel is visible. If you do not want a panel to be visible, uncheck the panel and it will be hidden from view:

  • Packet List: This is a list of all of the captured packets, where each line represents a single packet.
  • Packet Details: This displays the details of a single packet.
  • Packet Bytes: This is a hexadecimal representation of a single packet.

The next section outlines the options for display the time in Wireshark, along with how to provide name resolution.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.143.244.83