This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

How to extract packets related to different internet applications from mixture of packets captured by wireshark?

0

My problem is to separate packets related to multiple applications from all packets captured by wireshark when multiple applications are running over internet. Is there any way to extract or isolate packets according to application type such as www, mail, multimedia, p2p etc. plz reply me

asked 12 Apr '11, 05:24

Kuldeep's gravatar image

Kuldeep
1111
accept rate: 0%

edited 26 Feb '12, 22:21

cmaynard's gravatar image

cmaynard ♦♦
9.4k1038142


One Answer:

1

There are a lot of ways to do that. You could use the Protocol Hierarchy Statistics to get a list of all protocols Wireshark detected (which is more or less accurate), and then use the popup menu to filter the protocols you want to take a look at.

If the protocol you want isn't listed you need to find out what ports it usually uses and then filter for it yourself or find conversations using that port with the help of the Conversation Statistics. From there, once again you can right click and use the popup menu to filter for the connections you want to take a closer look at.

answered 12 Apr '11, 05:52

Jasper's gravatar image

Jasper ♦♦
23.8k551284
accept rate: 18%