Quick Filtering in Wireshark
After you have done a wireshark capture, you will most often want to cull out some of the information. You do this using filters. You can use the filter builder, which is a slow process, you can memorize what to type or you can simply right click 🙂
Right click on the exact piece of information you want to filter by (include or exclude) and choose “apply as filter”. This will allow you to quickly add or exclude it in the filter options.
I perfer to use Packetyzer. Its based off Ethereal, but just seems so much cleaner.
http://paglo.com/opensource/packetyzer_thankyou
Yar…I’ve gotten used to wireshark and it’s power…sooooo many options.