Wireshark Display Filters: Syntax, Useful Examples and SOC Use Cases

In 2026, mastering Wireshark display filters is more critical than ever for anyone in cybersecurity, network forensics, or ethical hacking. This blog is a comprehensive and practical guide to Wireshark filters — covering basic to advanced commands, real-world SOC analyst scenarios, and troubleshooting hacks. From TCP flags and ICMP errors to filtering HTTP GETs, DNS queries, TLS handshakes, and custom MAC/IP filters, this guide helps you analyze packets with precision. Whether you're a student, intern, or working pro, this resource will fast-track your ability to navigate traffic chaos and extract meaningful insights using Wireshark in 2026.

Jun 20, 2025 - 11:27
Updated: 7 days ago
105.7k
Wireshark Display Filters: Syntax, Useful Examples and SOC Use Cases

Quick answer: Wireshark display filters narrow a capture to the packets you care about. The syntax is field operator value, such as ip.addr == 10.0.0.1 or tcp.port == 443, combined with &&, || and!. Useful filters include dns, tcp.flags.syn == 1 && tcp.flags.ack == 0 for new connections, tls.handshake for TLS, and tcp.analysis.retransmission for network problems.

Key takeaways

  • A display filter hides packets after capture. A capture filter (BPF) limits what is recorded. They use different syntax.
  • The pattern is field operator value. Type a field into the filter bar and Wireshark autocompletes and colours it green or red.
  • Combine with && (and), || (or) and! (not). Use parentheses for grouping.
  • tcp.port == 80 matches either source or destination port. Use tcp.dstport or tcp.srcport for one direction.
  • Filters help to find leads. Always confirm what you see before calling traffic malicious. Capture only where you are authorised.

What is the syntax of a Wireshark display filter?

Most filters follow field operator value, for example ip.src == 192.168.1.10. Operators include ==, !=, >, <, contains (substring), matches (regular expression) and in (a set, such as tcp.port in {80 443 8080}). Combine tests with &&, || and !. The filter bar turns green when valid, red when not. The Wireshark documentation lists every field.

How is this different from a capture filter?

Capture filters such as host 10.0.0.1 and port 53 use BPF syntax and decide what is recorded. Display filters use Wireshark's own syntax and decide what you see. Capture broadly, then filter on screen unless the volume is huge. New to Wireshark? Start with the beginner tutorial.

Which filters should you know?

Addresses and ports

FilterWhat it shows
ip.addr == 10.0.0.1Packets to or from 10.0.0.1
ip.addr == 10.0.0.0/24Any address in the /24 subnet
!(ip.addr == 10.0.0.1)Everything except that host
ip.src == 10.0.0.1 && ip.dst == 10.0.0.9One direction between two hosts
tcp.port == 80TCP traffic with port 80 as source or destination
tcp.dstport == 443TCP traffic going to port 443
tcp.srcport < 1024TCP sent from a well-known port
tcp or udpOnly TCP or UDP

Protocols and application layer

FilterWhat it shows
dnsAll DNS traffic
dns.qry.name contains "example"DNS queries for names containing "example"
http.request.method == "GET"HTTP GET requests
http.request.method == "POST"HTTP POST requests (form or API submissions)
http.response.code == 404HTTP 404 responses
http.host == "www.example.com"HTTP to that host header
tls.handshakeTLS handshake messages
tls.handshake.type == 1TLS Client Hello
tls.handshake.extensions_server_namePackets that carry a TLS server name (SNI)
icmpPing and ICMP errors
icmp.type == 3Destination unreachable
arpAddress resolution traffic
frame contains "password"Any frame containing that text (only meaningful in unencrypted traffic)

TCP behaviour and problems

FilterWhat it shows
tcp.flags.syn == 1 && tcp.flags.ack == 0New connection attempts (SYN only)
tcp.flags == 0x012SYN-ACK responses
tcp.flags.reset == 1Connections reset
tcp.analysis.retransmissionRetransmitted segments, a sign of loss or congestion
tcp.analysis.flagsEverything Wireshark flags as a TCP problem
tcp.window_size == 0Zero window, receiver cannot accept more data

One correction to some older guides: tcp.port == 80 does not mean destination port 80. It matches either direction. Use tcp.dstport == 80 for destination only.

How do SOC analysts use filters in practice?

  • Possible port scan: filter tcp.flags.syn == 1 && tcp.flags.ack == 0, then use Statistics, Conversations to see one source touching many ports. Many SYNs with resets in return are a lead, not proof.
  • Beaconing or odd DNS: filter dns, sort by query name, look for very long random-looking names or repeated queries at regular intervals.
  • Cleartext credentials in a lab: filter http.request.method == "POST" and inspect the form data to see why HTTP is unsafe.
  • Unexpected outbound services: ip.src == 10.0.0.0/24 &&!(ip.dst == 10.0.0.0/24) && tcp.dstport!= 443 to list internal hosts talking to the internet on unusual ports.
  • Slow application: tcp.analysis.retransmission || tcp.analysis.zero_window to see whether the network or the server is the cause.

What tips make filtering faster?

  • Right-click a field in the details pane and choose Apply as Filter.
  • Save useful filters with the bookmark button, and add filter buttons for the ones you use daily.
  • Add important fields as columns, such as tcp.stream or the TLS server name.
  • Use Follow, TCP Stream to see one conversation.
  • Use Statistics, Protocol Hierarchy and Conversations before filtering, to see where the volume is.
  • Read the field name in the status bar when you click a field. That is what you type.

What can filters not do?

They cannot decrypt traffic. For HTTPS, you see handshakes and metadata unless you have session keys in a lab. They also do not decide intent. A SYN burst can be a scanner or a monitoring tool. Check against asset lists and logs.

Legal reminder

Capture only on networks you own or have written authorisation to monitor. Unauthorised interception is an offence under India's IT Act, and captures can contain personal data.

Next steps

To practise filters on real captures, see WebAsha's SOC training. Also read the most important Wireshark filters and Wireshark filters for OT monitoring.

Related reading

Frequently Asked Questions

A capture filter uses BPF syntax and limits which packets are recorded. A display filter uses Wireshark syntax and hides packets from view after capture. Display filters are more flexible, so beginners can capture broadly and filter on screen.

Use ip.addr == 10.0.0.1 for traffic to or from that address, ip.src or ip.dst for one direction, and ip.addr == 10.0.0.0/24 for a subnet. Add! to exclude, for example!(ip.addr == 10.0.0.1).

It matches TCP packets where either the source or the destination port is 80. For destination only use tcp.dstport == 80, and for source only use tcp.srcport == 80.

Use tcp.flags.syn == 1 && tcp.flags.ack == 0 to show SYN packets that start connections. Many SYNs from one source to many ports can indicate scanning, which you should confirm with other evidence.

No. Filters work on what Wireshark can see. HTTPS content is encrypted, so you see handshakes and metadata. In a lab you can decrypt your own browser traffic using session key logs.

Click the bookmark icon at the left of the filter bar to save it, or use the plus button to add a filter button. Saved filters appear in a menu so you can reuse them.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.