Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

How do I clear the capture window in Wireshark?

Tags:

wireshark

Is there a way to clear the capture window in Wireshark without restarting the capture or re-applying the filter? It's difficult to tell one set of traffic from another without looking very closely at the timestamp.

like image 337
Ryan Shripat Avatar asked Oct 14 '13 18:10

Ryan Shripat


People also ask

What does capture mean in Wireshark?

It captures network traffic on the local network and stores that data for offline analysis. Wireshark captures network traffic from Ethernet, Bluetooth, Wireless (IEEE. 802.11), Token Ring, Frame Relay connections, and more. Ed.

How do you change the capture filter in Wireshark?

To create or edit capture filters, select Manage Capture Filters from the capture filter bookmark menu or Capture → Capture Filters… ​ from the main menu. Display filters can be created or edited by selecting Manage Display Filters from the display filter bookmark menu or Analyze → Display Filters…

What is capture filter in Wireshark?

Capture filters are used for filtering when capturing packets and are discussed in Section 4.10, “Filtering while capturing”. Display filters are used for filtering which packets are displayed and are discussed below. For more information about display filter syntax, see the wireshark-filter(4) man page.


1 Answers

I don't see a way to clear the window, but hitting 'Restart the running live capture' seems to work.

You can therefore clear the window in WireShark by doing one of the following:

  • Clicking on the green shark-fin to the right of the red Stop button
  • Clicking on Capture > Restart
  • Hitting Ctrl-R.
like image 61
Ryan Shripat Avatar answered Sep 23 '22 02:09

Ryan Shripat