Start with a time-bounded question
Suppose a computer becomes slow during a backup. A short capture around that event can show which pairs of endpoints exchanged the most recorded data. It cannot by itself prove that the transfer was unwanted or that the internet link was saturated.
Open the conversation view
- Open your capture and choose Statistics, Conversations.
- Select the relevant protocol tab, such as IPv4, IPv6 or TCP.
- Sort by bytes to identify larger recorded transfers.
- Compare direction, start time and duration with the activity you expected.
A conversation represents traffic between endpoint pairs. TCP conversations include ports, so one IP pair can have several separate connections.
Respect the display-filter setting
If you already filtered the packet list, check whether Limit to display filter is enabled in the conversation window. That choice changes which traffic contributes to the view. Document it alongside the capture's start and stop time so another person can reproduce your conclusion.
Investigate one large transfer
Select the conversation and apply an appropriate filter. Examine packets and timing rather than naming it malicious from its size. A software update, cloud backup or video meeting can create a large legitimate transfer. Conversely, a harmful action may use little bandwidth.
Where useful, use an I/O graph to compare packet or byte activity over time. Check the graph's interval and units. Bytes, bits per second and application payload are different measurements; do not interchange them when estimating link utilisation.
Verify with another data source
Compare with the known application schedule, process-level connection information, router counters or backup logs. A packet capture on one interface sees only traffic at that vantage point. Traffic dropped before capture, offloading and other interfaces can affect interpretation.
Common mistakes
The busiest address may be a CDN serving several services. A large sent-byte count is not automatic proof of exfiltration. A conversation's duration does not equal the time a user spent on a website. Name-resolution labels can be helpful but should not replace the underlying addresses in a technical investigation.
Export selectively
Wireshark can copy conversation data for reporting. Review it for sensitive addresses and identifiers before sharing. Include scope, time window and filter state with the table. The useful result is an evidence-based explanation of the observed transfer, with uncertainty stated clearly.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.