User Guide

6.4. Building display filter expressions ........................................................... 110
6.4.1. Display filter fields .................................................................... 110
6.4.2. Comparing values ...................................................................... 110
6.4.3. Combining expressions ............................................................... 111
6.4.4. A common mistake .................................................................... 113
6.5. The "Filter Expression" dialog box .......................................................... 114
6.6. Defining and saving filters ..................................................................... 116
6.7. Finding packets .................................................................................... 118
6.7.1. The "Find Packet" dialog box ....................................................... 118
6.7.2. The "Find Next" command .......................................................... 119
6.7.3. The "Find Previous" command ..................................................... 119
6.8. Go to a specific packet .......................................................................... 120
6.8.1. The "Go Back" command ............................................................ 120
6.8.2. The "Go Forward" command ....................................................... 120
6.8.3. The "Go to Packet" dialog box ..................................................... 120
6.8.4. The "Go to Corresponding Packet" command .................................. 120
6.8.5. The "Go to First Packet" command ............................................... 120
6.8.6. The "Go to Last Packet" command ................................................ 120
6.9. Marking packets ................................................................................... 121
6.10. Time display formats and time references ................................................ 122
6.10.1. Packet time referencing ............................................................. 122
7. Advanced Topics ............................................................................................ 125
7.1. Introduction ........................................................................................ 125
7.2. Following TCP streams ......................................................................... 126
7.2.1. The "Follow TCP Stream" dialog box ............................................ 126
7.3. Time Stamps ....................................................................................... 128
7.3.1. Wireshark internals .................................................................... 128
7.3.2. Capture file formats ................................................................... 128
7.3.3. Accuracy .................................................................................. 128
7.4. Time Zones ......................................................................................... 130
7.4.1. Set your computer's time correct! .................................................. 131
7.4.2. Wireshark and Time Zones .......................................................... 131
7.5. Packet Reassembling ............................................................................ 133
7.5.1. What is it? ................................................................................ 133
7.5.2. How Wireshark handles it ........................................................... 133
7.6. Name Resolution ..................................................................................135
7.6.1. Name Resolution drawbacks ........................................................ 135
7.6.2. Ethernet name resolution (MAC layer) ........................................... 135
7.6.3. IP name resolution (network layer) ................................................ 136
7.6.4. IPX name resolution (network layer) ............................................. 136
7.6.5. TCP/UDP port name resolution (transport layer) .............................. 136
7.7. Checksums ......................................................................................... 137
7.7.1. Wireshark checksum validation .................................................... 137
7.7.2. Checksum offloading .................................................................. 138
8. Statistics ....................................................................................................... 140
8.1. Introduction ........................................................................................ 140
8.2. The "Summary" window ........................................................................ 141
8.3. The "Protocol Hierarchy" window ........................................................... 143
8.4. Endpoints ........................................................................................... 145
8.4.1. What is an Endpoint? .................................................................. 145
8.4.2. The "Endpoints" window ............................................................. 145
8.4.3. The protocol specific "Endpoint List" windows ............................... 146
8.5. Conversations ...................................................................................... 147
8.5.1. What is a Conversation? .............................................................. 147
8.5.2. The "Conversations" window ....................................................... 147
8.5.3. The protocol specific "Conversation List" windows .......................... 147
8.6. The "IO Graphs" window ....................................................................... 148
8.7. Service Response Time ......................................................................... 150
8.7.1. The "Service Response Time DCE-RPC" window ............................ 150
8.8. The protocol specific statistics windows ................................................... 152
9. Customizing Wireshark .................................................................................... 154
9.1. Introduction ........................................................................................ 154
9.2. Start Wireshark from the command line .................................................... 155
Wireshark User's Guide
vi