Wireshark Display Filters: Syntax, Useful Examples and SOC Use Cases
In 2026, mastering Wireshark display filters is more critical than ever for anyone in cybersecurity, network forensics, or ethical hacking. This blog is a comprehensive and practical guide to Wireshark filters — covering basic to advanced commands, real-world SOC analyst scenarios, and troubleshooting hacks. From TCP flags and ICMP errors to filtering HTTP GETs, DNS queries, TLS handshakes, and custom MAC/IP filters, this guide helps you analyze packets with precision. Whether you're a student, intern, or working pro, this resource will fast-track your ability to navigate traffic chaos and extract meaningful insights using Wireshark in 2026.
Quick answer: Wireshark display filters narrow a capture to the packets you care about. The syntax is field operator value, such as ip.addr == 10.0.0.1 or tcp.port == 443, combined with &&, || and!. Useful filters include dns, tcp.flags.syn == 1 && tcp.flags.ack == 0 for new connections, tls.handshake for TLS, and tcp.analysis.retransmission for network problems.
Key takeaways
- A display filter hides packets after capture. A capture filter (BPF) limits what is recorded. They use different syntax.
- The pattern is field operator value. Type a field into the filter bar and Wireshark autocompletes and colours it green or red.
- Combine with && (and), || (or) and! (not). Use parentheses for grouping.
- tcp.port == 80 matches either source or destination port. Use tcp.dstport or tcp.srcport for one direction.
- Filters help to find leads. Always confirm what you see before calling traffic malicious. Capture only where you are authorised.
What is the syntax of a Wireshark display filter?
Most filters follow field operator value, for example ip.src == 192.168.1.10. Operators include ==, !=, >, <, contains (substring), matches (regular expression) and in (a set, such as tcp.port in {80 443 8080}). Combine tests with &&, || and !. The filter bar turns green when valid, red when not. The Wireshark documentation lists every field.
How is this different from a capture filter?
Capture filters such as host 10.0.0.1 and port 53 use BPF syntax and decide what is recorded. Display filters use Wireshark's own syntax and decide what you see. Capture broadly, then filter on screen unless the volume is huge. New to Wireshark? Start with the beginner tutorial.
Which filters should you know?
Addresses and ports
| Filter | What it shows |
|---|---|
ip.addr == 10.0.0.1 | Packets to or from 10.0.0.1 |
ip.addr == 10.0.0.0/24 | Any address in the /24 subnet |
!(ip.addr == 10.0.0.1) | Everything except that host |
ip.src == 10.0.0.1 && ip.dst == 10.0.0.9 | One direction between two hosts |
tcp.port == 80 | TCP traffic with port 80 as source or destination |
tcp.dstport == 443 | TCP traffic going to port 443 |
tcp.srcport < 1024 | TCP sent from a well-known port |
tcp or udp | Only TCP or UDP |
Protocols and application layer
| Filter | What it shows |
|---|---|
dns | All DNS traffic |
dns.qry.name contains "example" | DNS queries for names containing "example" |
http.request.method == "GET" | HTTP GET requests |
http.request.method == "POST" | HTTP POST requests (form or API submissions) |
http.response.code == 404 | HTTP 404 responses |
http.host == "www.example.com" | HTTP to that host header |
tls.handshake | TLS handshake messages |
tls.handshake.type == 1 | TLS Client Hello |
tls.handshake.extensions_server_name | Packets that carry a TLS server name (SNI) |
icmp | Ping and ICMP errors |
icmp.type == 3 | Destination unreachable |
arp | Address resolution traffic |
frame contains "password" | Any frame containing that text (only meaningful in unencrypted traffic) |
TCP behaviour and problems
| Filter | What it shows |
|---|---|
tcp.flags.syn == 1 && tcp.flags.ack == 0 | New connection attempts (SYN only) |
tcp.flags == 0x012 | SYN-ACK responses |
tcp.flags.reset == 1 | Connections reset |
tcp.analysis.retransmission | Retransmitted segments, a sign of loss or congestion |
tcp.analysis.flags | Everything Wireshark flags as a TCP problem |
tcp.window_size == 0 | Zero window, receiver cannot accept more data |
One correction to some older guides: tcp.port == 80 does not mean destination port 80. It matches either direction. Use tcp.dstport == 80 for destination only.
How do SOC analysts use filters in practice?
- Possible port scan: filter
tcp.flags.syn == 1 && tcp.flags.ack == 0, then use Statistics, Conversations to see one source touching many ports. Many SYNs with resets in return are a lead, not proof. - Beaconing or odd DNS: filter
dns, sort by query name, look for very long random-looking names or repeated queries at regular intervals. - Cleartext credentials in a lab: filter
http.request.method == "POST"and inspect the form data to see why HTTP is unsafe. - Unexpected outbound services:
ip.src == 10.0.0.0/24 &&!(ip.dst == 10.0.0.0/24) && tcp.dstport!= 443to list internal hosts talking to the internet on unusual ports. - Slow application:
tcp.analysis.retransmission || tcp.analysis.zero_windowto see whether the network or the server is the cause.
What tips make filtering faster?
- Right-click a field in the details pane and choose Apply as Filter.
- Save useful filters with the bookmark button, and add filter buttons for the ones you use daily.
- Add important fields as columns, such as
tcp.streamor the TLS server name. - Use Follow, TCP Stream to see one conversation.
- Use Statistics, Protocol Hierarchy and Conversations before filtering, to see where the volume is.
- Read the field name in the status bar when you click a field. That is what you type.
What can filters not do?
They cannot decrypt traffic. For HTTPS, you see handshakes and metadata unless you have session keys in a lab. They also do not decide intent. A SYN burst can be a scanner or a monitoring tool. Check against asset lists and logs.
Legal reminder
Capture only on networks you own or have written authorisation to monitor. Unauthorised interception is an offence under India's IT Act, and captures can contain personal data.
Next steps
To practise filters on real captures, see WebAsha's SOC training. Also read the most important Wireshark filters and Wireshark filters for OT monitoring.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0