This is our old Q&A Site. Please post any new questions and answers at

Can I run wireshark without doing an install? We have some prod servers that we cannot install the program until the weekend and need to run it without an install?

Thank you, Dario

asked 02 Nov '11, 14:14

lastcall1969's gravatar image

accept rate: 0%

You can download the sources and compile Wireshark yourself, then you can run it from the build directory without doing an install. Or, if your production servers are running Windows, then it might be easier for you to download and install either the U3 or portableapps versions on a compatible USB flash drive and run it from there instead.

If your production servers are running Windows and you want to capture live traffic as opposed to only reading existing capture files, then you will still have to install WinPcap though.

permanent link

answered 02 Nov '11, 17:48

cmaynard's gravatar image

cmaynard ♦♦
accept rate: 20%

If the production servers have, for example, tcpdump or snoop installed on them (many UN*Xes may have tcpdump installed; Solaris machines might have snoop installed), you could use tcpdump with -s 0 -w or snoop with -o to capture the network traffic, and then copy it to a machine that has Wireshark installed on it and open the capture there.

permanent link

answered 03 Nov '11, 18:30

Guy%20Harris's gravatar image

Guy Harris ♦♦
accept rate: 19%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 02 Nov '11, 14:14

question was seen: 4,890 times

last updated: 03 Nov '11, 18:30

p​o​w​e​r​e​d by O​S​Q​A