cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
613
Views
0
Helpful
1
Replies

Wireshark Setup

winston.lewis
Level 1
Level 1

Does anyone use wireshark to capture packets, if yes, what are the steps to begin the process? The ports have already been spanned and ready to go.

Please advise....

1 Reply 1

Joe Clarke
Cisco Employee
Cisco Employee

I use it all the time.  It's very easy to use.  Just plug your wireshark host into the destination SPAN port and go to Capture > Start.  That will start capturing all ports spanned from the source.  If you want to do filtering of these packets as the capture is running, go to Capture > Options and define a capture filter.  For example, to filter on all HTTP traffic, use the filter "tcp port 80".

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: