Quick Start Guide

Wireshark Quickstart Guide
11
III) What if I can’t find any packets?
If you don’t see any packets while Wireshark is performing the
capture, you may have de-selected the option to “Update
packets in real time (item 1 in Figure 4). When the capture
stops, you should see Wireshark process and load each packet
which was captured.
There are several things to check out if you don’t see packets
after you end the capture.
1) When you were setting up Wireshark, did you select the
network adapter that is being used to interface with the
network?
Refer to section Error! Reference source not found.,
Figure 2, and Figure 3 in Chapter 1: Getting Started. You
can also change the interface in a drop-down box the
Capture Options dialog
2) Are you using a wireless connection on a Windows
machine?
Wireshark is not able to capture packets on some wireless
connections within Windows. Refer to section IV) in
Appendix 1 for a possible workaround and more
information.
3) Are you using filters?
Wireshark can filter results so that only certain types of
packets are captured. If the capture filter is set and no
packets matched the filter then you will have captured no
packets. There is nothing you can do except repeat the
capture either without the capture filter or ensure that the
specified packets are created. There is also a display filter
that will hide any packet not meeting a specified condition.
An example of a filter condition would be to only display
packets sent to/from a specific IP address. If you set a filter,
and then have no traffic that matches the filter, then you will
not see any packets. Click the “clear” button next to the
display filter to view all packets (see Figure 11). For more
information on filters refer to Appendix 2.
4) Did you create any traffic for Wireshark to filter?
After you go to the “Capture” menu and choose “Start”, you
must leave Wireshark running. If the Capture Info dialog is
Filters can ‘hide’ your
traffic. Even if you
didn’t set a filter, some
commands
automatically set
filters. Refer to
Appendix 2 to find out
how to clear filters.