This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi all,

I'm a Wireshark beginner and I have a question about it:

How does one go about finding services in Wireshark, specifically, the question is asking 'What services are running in the network capture?'

Would this relate to the application layer and services that run within it? Any help would be greatly appreciated

Lambert

asked 12 Feb '13, 07:00

Lambert84's gravatar image

Lambert84
1111
accept rate: 0%


'What services are running in the network capture?'

'services' is not the right term in case of Wireshark. What you see in Wireshark is (mostly) TCP and UDP conversations. Some TCP/UDP ports (mail:25, http:80,ssh:22, etc.) are tied to 'services' (by convention). So, you need to know what TCP/UDP port your service/application is using and then you can filter for that.

You get a brief overview of protocols/ports/services by this:

Statistics -> Potocol Hierarchy

If you need a more detailed view, you need to actually look at packets and filter for whatever you need.

If you need just an overview what is going on in your network, a network forensic tool may be better suited for you (e.g. Network Miner, Xplico or similar).

Regards
Kurt

permanent link

answered 12 Feb '13, 07:22

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×1,620
×24
×21

question asked: 12 Feb '13, 07:00

question was seen: 14,565 times

last updated: 12 Feb '13, 07:22

p​o​w​e​r​e​d by O​S​Q​A