This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

My problem is to separate packets related to multiple applications from all packets captured by wireshark when multiple applications are running over internet. Is there any way to extract or isolate packets according to application type such as www, mail, multimedia, p2p etc. plz reply me

asked 12 Apr '11, 05:24

Kuldeep's gravatar image

Kuldeep
1111
accept rate: 0%

edited 26 Feb '12, 22:21

cmaynard's gravatar image

cmaynard ♦♦
9.4k1038142


There are a lot of ways to do that. You could use the Protocol Hierarchy Statistics to get a list of all protocols Wireshark detected (which is more or less accurate), and then use the popup menu to filter the protocols you want to take a look at.

If the protocol you want isn't listed you need to find out what ports it usually uses and then filter for it yourself or find conversations using that port with the help of the Conversation Statistics. From there, once again you can right click and use the popup menu to filter for the connections you want to take a closer look at.

permanent link

answered 12 Apr '11, 05:52

Jasper's gravatar image

Jasper ♦♦
23.8k551284
accept rate: 18%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×248
×41
×8
×1

question asked: 12 Apr '11, 05:24

question was seen: 3,546 times

last updated: 26 Feb '12, 22:21

p​o​w​e​r​e​d by O​S​Q​A