Network tools · Network tools

Wireshark Display Filters and Capture Filters: Practical Examples

Wireshark has two filter languages. A capture filter decides which packets are collected. A display filter decides which already-collected packets are shown. Start with a modest capture filter, then use display filters to investigate the resulting file. Packets excluded during capture cannot be recovered by changing the display filter.

Scope: Modern Wireshark; the filter bar validates syntax. Fields vary with dissector and release.

Match the syntax to the field #

TaskCapture filterDisplay filter
One IPv4 hosthost 192.0.2.20ip.addr == 192.0.2.20
One IPv6 hosthost 2001:db8::20ipv6.addr == 2001:db8::20
TCP port 443tcp port 443tcp.port == 443
UDP port 53udp port 53udp.port == 53
IPv4 subnetnet 192.0.2.0/24ip.addr == 192.0.2.0/24

Capture syntax such as host does not belong in the display-filter bar. Conversely, ip.addr == is not a libpcap capture expression. The display filter dns selects traffic Wireshark has dissected as DNS, which is a different question from selecting every packet on port 53.

Follow one connection #

Follow one connection
Network tools · Wireshark display-filter bar

Read-only

Replace these example values: 192.0.2.20.

ip.addr == 192.0.2.20 && tcp.port == 443
Read-only
tcp.stream == 4
Read-only
tcp.flags.syn == 1 && tcp.flags.ack == 0
Read-only
tcp.flags.reset == 1
Read-only
tcp.analysis.retransmission || tcp.analysis.fast_retransmission
Read-only
tcp.analysis.zero_window

Select a packet from the connection, find its TCP stream index, then substitute that number for 4. Stream numbers are local to the capture; the same connection can have another index in a second file. A stream filter prevents unrelated connections to the same server from confusing the timeline.

Turn a filter into a diagnosis #

A SYN without a visible SYN-ACK is evidence about this observation point. It is not automatic proof that the server is down. A reset means a connection was rejected or closed by an endpoint or intermediary; inspect direction and timing. Retransmission analysis is Wireshark's interpretation of the captured sequence, so missing or reordered capture packets can affect the result.

A zero-window indication directs attention toward receiver buffering or application consumption. Compare both directions and the duration before deciding whether the event explains the user-visible delay. Brief events and repeated stalls are different findings.

Preserve context #

Keep the original capture and save the filter used in your incident notes. Include source, destination, protocol and reproduction time. Avoid sharing an unrestricted PCAP when a smaller authorized sample is sufficient. Display filtering alone does not remove hidden packets from the underlying file; export the intended packet subset when preparing evidence for another party.

Sources

Documentation reviewed: 8 October 2026