Relationship to tcpdump¶
Wireshark and tshark (its CLI counterpart) share libpcap with tcpdump, but add a second filtering layer: display filters, which run against the fully-decoded packet (any protocol field, any layer) rather than tcpdump's BPF capture filters. This is the practical dividing line — capture filters (BPF) decide what gets recorded; display filters decide what you're looking at afterward, and can express things BPF cannot, like "show me only retransmitted TCP segments" (see the tcpdump guide for more on this distinction).
Common display filter examples¶
tcp.port == 443 # traffic on a specific port
ip.addr == 192.168.1.10 # traffic to/from a specific host
tcp.flags.syn == 1 && tcp.flags.ack == 0 # SYN packets only (new connections)
tls.handshake.extensions_server_name # TLS SNI — which hostnames were requested
http.request # HTTP requests only
tcp.analysis.retransmission # retransmitted segments (tcpdump can't do this)
Opening a capture made elsewhere¶
wireshark capture.pcap
Remote capture piped straight in over SSH (no intermediate file):
ssh user@remote-host "tcpdump -i eth0 -U -s0 -w -" | wireshark -k -i -
Following a stream¶
Right-click any packet → Follow → TCP Stream (or UDP/HTTP/TLS Stream) to reassemble and view the full conversation in order, rather than packet-by-packet — the fastest way to read what was actually said in a plaintext protocol exchange.
CLI equivalent: tshark¶
For scripting or headless boxes, tshark gives the same dissection engine without the GUI:
tshark -r capture.pcap -Y "http.request" # display-filter a saved capture
tshark -r capture.pcap -Y "tls.handshake.extensions_server_name" \
-T fields -e tls.handshake.extensions_server_name # extract just the SNI field
tshark -i eth0 -f "tcp port 443" # live capture with a BPF capture filter
Further reading¶
- Wireshark display filter reference
- See tcpdump for capture-side filtering and remote capture workflows