Control what the sniffer shows you to avoid information overload
Last time we took a look at how to perform a quick capture of some sample network traffic using Wireshark. The wealth of information that you may see can be confusing, so your next step might be to gain some control over what you actually need to see. First, I like to configure the columns in the uppermost “packet list” pane. You might expect to find this capability on the View menu, but it’s really on the Edit menu under Preferences, which will feel familiar to you Mac folks. Under “User Interface,” choose Columns and you’ll see a list of the columns that will appear in the packet display pane. You can delete any columns that seem irrelevant to you; add new ones (the “Format” drop-down actually specifies the data to be displayed, not the format!); and reorder the columns using the arrows at right. Typically you will want to see the source, destination, protocol, and info formats; beyond that, it’s up to you. If you’re troubleshooting slow behavior, you’ll probably want the Time format as well. While we’re here in the Preferences window, click the Capture setting in the windowpane to the left. Here you may recognize some of the options that were available to you in yesterday’s posting when we initiated our first actual capture. The Preferences window lets you set defaults for various Wireshark dialog boxes. Now, click OK, and you should be back at the Wireshark main screen. There are three windowpanes in this screen. The packet list pane appears on top. Below it is a “packet details” pane that provides more details about whichever packet in the packet list pane is highlighted. The “packet bytes” pane is below that; it’s the raw view of the packet contents. Try this: Click on different lines in the packet details pane, and see what happens in the packet bytes pane. Wireshark highlights the bytes that correspond to the information you click in the packet details pane. Pretty cool. The three primary panes may be resized by dragging the horizontal bars that separate them. However, depending on the kind of analysis you intend to perform, you may or may not need to see the packet bytes pane. You can selectively enable or disable the display of any of the three panes by using the View menu. Go ahead and turn off the packet bytes pane for the time being. In tomorrow’s posting, we’ll apply a filter to the packets displayed in the packet list pane.




