Capturing traffic

If you are getting ready to capture traffic, you'll want to set Wireshark up properly. You can find the Capture label in the middle of the screen. Once there, you can apply a capture filter in the space provided. Below the capture filter area, you'll see a list of interfaces, with a moving symbol next to the active interface(s). The moving symbol is called a sparkline, which identifies an interface, and the lines represent actively exchanging data.

The capture filter allows you to add a capture filter. If you do use a capture filter, be aware that it will limit what you capture to only what you have filtered on, and you may miss the traffic that can help with your analysis.

To the right of the capture filter, you will see a drop-down menu reading All interfaces shown. If you want to remove any of the classes of interfaces (such as Wired or Virtual), you can select one from the drop-down menu, as shown in the following screenshot:

Capture options

In the list of interfaces, you will see the various connections. One of the interfaces may be the USBPcap, which will be available if you installed the USBPcap driver. This is a fairly new option that may be helpful to use during troubleshooting.

The last thing on the interface you'll find is a few links that can provide more information.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.216.233.58