Packet Path/

10 Wireshark Display Filters You'll Use Every Week

Display filters turn a million-packet capture into an answer. Ten patterns that cover 90% of real troubleshooting, plus the two mistakes everyone makes.

Troubleshooting · Beginner · 8 min · September 30, 2026

Illustration of a magnifying lens over flowing packet streams

The one distinction that matters

Wireshark speaks two filter languages. Capture filters (BPF, used when capturing) decide what gets recorded — syntax like host 192.168.1.10 and tcp port 443. Display filters hide what you don't want to see after the fact — syntax like ip.addr == 192.168.1.10 && tcp.port == 443. Newcomers paste one into the other daily. Capture filters save disk; display filters save sanity.

The ten

  1. ip.addr == 192.168.1.10 — everything to or from a host. Use ip.src/ip.dst when direction matters, and ipv6.addr for v6.
  2. tcp.port == 443 — a service across all hosts. Combine: tcp.port == 443 && ip.addr == 192.168.1.10.
  3. dns — all DNS. Pairs with dns.qry.name contains "example.com" to watch one name.
  4. icmp — ping and traceroute. Split request/reply with icmp.type == 8 (echo request) / == 0 (reply).
  5. arp — who-has traffic. Flooding ARP is a classic misconfig signature (proxy ARP, duplicates, missing gateways).
  6. tcp.flags.syn == 1 && tcp.flags.ack == 0 — new connection attempts. SYNs with no SYN-ACK = the service is down or filtered.
  7. tcp.analysis.retransmission — the start of every "it's slow" case. Add tcp.analysis.duplicate_ack for the mirror image.
  8. http.response.code >= 400 — failing HTTP. With TLS-everywhere, this only helps on unencrypted flows — which is itself diagnostic.
  9. frame.len > 1400 — jumbo or fragmented traffic patterns; swap in ip.flags.mf == 1 to hunt fragmentation.
  10. tcp.stream eq 7 — one TCP conversation; right-click any packet → Follow → TCP Stream does this for you.

The subtraction trick

Sometimes the answer is what remains when noise is gone: !(arp || icmp || dns || stp) strips the chatter. On noisy captures, excluding the top three protocols by volume (Statistics → Protocol Hierarchy) reveals what's actually wrong.

Pro moveRight-click any field → Apply as Filter → Selected. Then edit the generated filter text. You learn the language by editing perfect examples instead of writing from memory.

SSD-era tip: capture less, not more

On a 1 Gbps link, promiscuous capture fills disks fast. Use capture filters (host x && port y), ring buffers, and capture file rotation (Capture → Options) so the incident capture is 50 MB of the interesting thing, not 50 GB of everything.

One last distinction worth keeping straight: display filters tell you what the wire actually did, packet by packet. They can't tell you what a firewall would do — that's a rule-order question, answered on paper by reading the ACL top-down the way the hardware does. Paste your policy into the ACL rule analyzer and it finds the shadowed and redundant rules no capture will ever show you, because shadowed traffic never reaches the wire in the first place.

Key takeaways

Keep reading