There are a large number of parameters you can change in the Preferences window, including what data is presented, where files are saved by default, what is the default interface that Wireshark captures data from, and many more.
What we will refer to in this chapter are the common parameters that when changed will help us with various capture scenarios.
For configuring User Interface, we will choose the Preferences option from the Edit menu. You will get the following window:
We will look at the configuration of the following parameters:
In this section we will see how to change parameters that will help in working with Wireshark.
The default columns that we see in the packet pane are the number, time, source and destination addresses, protocol, length, and information columns, as shown in the following screenshot:
To add a new column to the packet pane:
tcp.window_size
to view the TCP window size (that influences performance).ip.ttl
to view the IP TTL (Time-To-Live) parameter of every packet.rtp.marker
to view every instance of a marker set in an RTP packet.There are some parameters that can be configured before capturing data. In the Preferences window choose the Capture menu, and the following window will come up:
For changing the default interface that the capture will start from, just click on the Edit button, and mark the interface you would like to be the default. Of course you can change it every time you start a new capture, this is only the default.
Wireshark supports Name Resolution in three layers:
The Wireshark default is to resolve layer-2 MAC addresses and layer-4 TCP/UDP port numbers. Resolving IP addresses can slow down Wireshark due to a large amount of DNS queries that it uses; therefore, use it carefully.
Very simple. This is the configuration menu for the Wireshark. Here you can configure parameters as described in this recipe, along with some other parameters. You can refer to Wireshark manuals at www.wireshark.org for further information.
18.116.21.229