MYTHOSAI

Tool tutorials / PRACTICAL GUIDE

Wireshark display filters you can explain

Find DNS, TLS and one host’s traffic without confusing display and capture filter syntax.

Before you start

Wireshark and a small authorised capture already open.

Keep filtering stages separate

A capture filter controls what is recorded. A display filter selects what you see from packets already recorded. Applying a display filter does not remove the other packets from the file, and its syntax is not interchangeable with capture-filter syntax.

Try one expression at a time

Enter these separately in Wireshark's display-filter bar:

text
dns
tls
ip.addr == 192.168.50.10
tcp.port == 443
dns && ip.addr == 192.168.50.10

The address is a lab example. Replace it with one visible in your sample. dns and tls select packets Wireshark has dissected as those protocols. The address filter matches either source or destination. The TCP port filter likewise matches either side, not only the server's listening port.

Build from a field you can see

  1. Select a packet related to your question.
  2. Expand its details and locate the actual field.
  3. Use the right-click Apply as Filter option to create an expression.
  4. Read the generated field name and value before combining it with another condition.

This is safer than memorising filters without understanding what they select. Parentheses can make combined expressions easier to read and prevent ambiguity in your own reasoning.

Verify with packet counts

Compare displayed and total packet counts. Clear the display filter and confirm the original packets remain. Inspect a matching packet to ensure the condition means what you intended.

For an IPv6 conversation, an IPv4-only field is the wrong tool; use the appropriate IPv6 fields or Wireshark's broader address expressions for your question.

Common mistakes

An empty dns result does not prove there was no name lookup. The answer may have been cached, DNS may be encrypted, or you may be looking at the wrong interface. tcp.port == 443 does not prove all selected traffic is ordinary HTTPS. A TLS packet is not automatically a complete web request.

Protect the recording

A display filter is not sanitisation. Sharing the filtered-looking capture can still expose every original packet unless you deliberately export a selected subset and review it. Even a subset may contain sensitive data. Keep raw captures private and use harmless lab samples for teaching.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.