
Learn Wireshark
By :

While capturing traffic, or analyzing a pre-captured file, display filters help to narrow the scope and home in on specific types of traffic. It's not uncommon to have a capture with over 3,000 packets containing many different types of traffic.
When you launch Wireshark, you will see the startup screen. Across the top, below the icons, is the filter toolbar. Within the toolbar is the text Apply a display filter…, where you can easily apply and edit display filters, as shown here:
Figure 7.6 – Wireshark startup screen
You can create a simple filter on any of the protocols Wireshark supports by using a single protocol or adding a logical operator. For example, if you want to see TCP or ARP traffic, then you would use the tcp || arp
display filter.
Wireshark's display filters can easily be modified. The following section illustrates how you can edit the display filters to customize your workflow.
...Change the font size
Change margin width
Change background colour