10 Wireshark Display Filters You'll Use Every Week
Display filters turn a million-packet capture into an answer. Ten patterns that cover 90% of real troubleshooting, plus the two mistakes everyone makes.
The one distinction that matters
Wireshark speaks two filter languages. Capture filters (BPF, used when capturing) decide what gets recorded — syntax like host 192.168.1.10 and tcp port 443. Display filters hide what you don't want to see after the fact — syntax like ip.addr == 192.168.1.10 && tcp.port == 443. Newcomers paste one into the other daily. Capture filters save disk; display filters save sanity.
The ten
ip.addr == 192.168.1.10— everything to or from a host. Useip.src/ip.dstwhen direction matters, andipv6.addrfor v6.tcp.port == 443— a service across all hosts. Combine:tcp.port == 443 && ip.addr == 192.168.1.10.dns— all DNS. Pairs withdns.qry.name contains "example.com"to watch one name.icmp— ping and traceroute. Split request/reply withicmp.type == 8(echo request) /== 0(reply).arp— who-has traffic. Flooding ARP is a classic misconfig signature (proxy ARP, duplicates, missing gateways).tcp.flags.syn == 1 && tcp.flags.ack == 0— new connection attempts. SYNs with no SYN-ACK = the service is down or filtered.tcp.analysis.retransmission— the start of every "it's slow" case. Addtcp.analysis.duplicate_ackfor the mirror image.http.response.code >= 400— failing HTTP. With TLS-everywhere, this only helps on unencrypted flows — which is itself diagnostic.frame.len > 1400— jumbo or fragmented traffic patterns; swap inip.flags.mf == 1to hunt fragmentation.tcp.stream eq 7— one TCP conversation; right-click any packet → Follow → TCP Stream does this for you.
The subtraction trick
Sometimes the answer is what remains when noise is gone: !(arp || icmp || dns || stp) strips the chatter. On noisy captures, excluding the top three protocols by volume (Statistics → Protocol Hierarchy) reveals what's actually wrong.
SSD-era tip: capture less, not more
On a 1 Gbps link, promiscuous capture fills disks fast. Use capture filters (host x && port y), ring buffers, and capture file rotation (Capture → Options) so the incident capture is 50 MB of the interesting thing, not 50 GB of everything.
One last distinction worth keeping straight: display filters tell you what the wire actually did, packet by packet. They can't tell you what a firewall would do — that's a rule-order question, answered on paper by reading the ACL top-down the way the hardware does. Paste your policy into the ACL rule analyzer and it finds the shadowed and redundant rules no capture will ever show you, because shadowed traffic never reaches the wire in the first place.
- Display filters (wireshark) and capture filters (BPF) are different languages — learn both.
- ip.addr, tcp.port, and dns.qry.name solve most "who talked to whom" questions.
- tcp.analysis.retransmission is where you start every slowness case.
- Right-click any field to Apply as Filter — no typing required.