Andrew Mercer
on this page

Relationship to tcpdump

Wireshark and tshark (its CLI counterpart) share libpcap with tcpdump, but add a second filtering layer: display filters, which run against the fully-decoded packet (any protocol field, any layer) rather than tcpdump's BPF capture filters. This is the practical dividing line — capture filters (BPF) decide what gets recorded; display filters decide what you're looking at afterward, and can express things BPF cannot, like "show me only retransmitted TCP segments" (see the tcpdump guide for more on this distinction).

Common display filter examples

tcp.port == 443                      # traffic on a specific port
ip.addr == 192.168.1.10              # traffic to/from a specific host
tcp.flags.syn == 1 && tcp.flags.ack == 0   # SYN packets only (new connections)
tls.handshake.extensions_server_name         # TLS SNI — which hostnames were requested
http.request                          # HTTP requests only
tcp.analysis.retransmission          # retransmitted segments (tcpdump can't do this)

Opening a capture made elsewhere

wireshark capture.pcap

Remote capture piped straight in over SSH (no intermediate file):

ssh user@remote-host "tcpdump -i eth0 -U -s0 -w -" | wireshark -k -i -

Following a stream

Right-click any packet → Follow → TCP Stream (or UDP/HTTP/TLS Stream) to reassemble and view the full conversation in order, rather than packet-by-packet — the fastest way to read what was actually said in a plaintext protocol exchange.

CLI equivalent: tshark

For scripting or headless boxes, tshark gives the same dissection engine without the GUI:

tshark -r capture.pcap -Y "http.request"                                    # display-filter a saved capture
tshark -r capture.pcap -Y "tls.handshake.extensions_server_name" \
  -T fields -e tls.handshake.extensions_server_name                          # extract just the SNI field
tshark -i eth0 -f "tcp port 443"                                             # live capture with a BPF capture filter

Further reading