Match the syntax to the field #
| Task | Capture filter | Display filter |
|---|---|---|
| One IPv4 host | host 192.0.2.20 | ip.addr == 192.0.2.20 |
| One IPv6 host | host 2001:db8::20 | ipv6.addr == 2001:db8::20 |
| TCP port 443 | tcp port 443 | tcp.port == 443 |
| UDP port 53 | udp port 53 | udp.port == 53 |
| IPv4 subnet | net 192.0.2.0/24 | ip.addr == 192.0.2.0/24 |
Capture syntax such as host does not belong in the display-filter bar. Conversely, ip.addr == is not a libpcap capture expression. The display filter dns selects traffic Wireshark has dissected as DNS, which is a different question from selecting every packet on port 53.
Follow one connection #
Follow one connection
Network tools · Wireshark display-filter bar
Replace these example values: 192.0.2.20.
ip.addr == 192.0.2.20 && tcp.port == 443tcp.stream == 4tcp.flags.syn == 1 && tcp.flags.ack == 0tcp.flags.reset == 1tcp.analysis.retransmission || tcp.analysis.fast_retransmissiontcp.analysis.zero_windowSelect a packet from the connection, find its TCP stream index, then substitute that number for 4. Stream numbers are local to the capture; the same connection can have another index in a second file. A stream filter prevents unrelated connections to the same server from confusing the timeline.
Turn a filter into a diagnosis #
A SYN without a visible SYN-ACK is evidence about this observation point. It is not automatic proof that the server is down. A reset means a connection was rejected or closed by an endpoint or intermediary; inspect direction and timing. Retransmission analysis is Wireshark's interpretation of the captured sequence, so missing or reordered capture packets can affect the result.
A zero-window indication directs attention toward receiver buffering or application consumption. Compare both directions and the duration before deciding whether the event explains the user-visible delay. Brief events and repeated stalls are different findings.
Preserve context #
Keep the original capture and save the filter used in your incident notes. Include source, destination, protocol and reproduction time. Avoid sharing an unrestricted PCAP when a smaller authorized sample is sufficient. Display filtering alone does not remove hidden packets from the underlying file; export the intended packet subset when preparing evidence for another party.
Sources
Documentation reviewed: 8 October 2026