Skip to main content
TrustRadius
Wireshark

Wireshark

Overview

What is Wireshark?

Wireshark is a free and open source network troubleshooting tool.

Read more
Recent Reviews

TrustRadius Insights

Wireshark, a widely utilized network traffic analysis tool, has proven to be invaluable for various user experiences and use cases. Cyber …
Continue reading

Indispensable tool

9 out of 10
October 31, 2022
Incentivized
Its port scans help you find the problem quickly. Recently I had to analyze a company because there was so much traffic on the network.
Continue reading

To Wireshark or not

9 out of 10
October 31, 2022
We use Wireshark in a multitude of ways. First, we troubleshoot connectivity issues with it, second, we use it for Firewall ruleset tests …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Return to navigation

Pricing

View all pricing

Wireshark

Free

On Premise

Entry-level set up fee?

  • No setup fee

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services
Return to navigation

Product Demos

Local and Remote Sniffing with Wireshark

YouTube

Wireshark demo (simple http)

YouTube

Saving Files From Wireshark

YouTube

Brim Demo

YouTube

How to Use Wireshark's Follow TCP Stream Feature

YouTube

Wireshark SIP Capture

YouTube
Return to navigation

Product Details

What is Wireshark?

Wireshark is a free and open source network troubleshooting tool.

Wireshark Technical Details

Deployment TypesOn-premise
Operating SystemsWindows, Linux, Mac
Mobile ApplicationNo

Frequently Asked Questions

Wireshark is a free and open source network troubleshooting tool.

Wireshark starts at $0.

Reviewers rate Support Rating highest, with a score of 10.

The most common users of Wireshark are from Mid-sized Companies (51-1,000 employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(135)

Community Insights

TrustRadius Insights are summaries of user sentiment data from TrustRadius reviews and, when necessary, 3rd-party data sources. Have feedback on this content? Let us know!

Wireshark, a widely utilized network traffic analysis tool, has proven to be invaluable for various user experiences and use cases. Cyber security professionals rely on Wireshark for research and investigation, allowing them to check network traffic from applications and ensure there are no abnormalities. The software's versatility is demonstrated by its utilization in setting up Capture the Flag challenges, making it an engaging tool for recruiting purposes. Additionally, Wireshark is essential for monitoring network traffic and troubleshooting network-related issues, saving time and effort in problem-solving. It enables system administrators and network administrators to dissect network packets in detail, extract relevant network information, and quickly identify and resolve network problems. The software's free and open-source nature provides cost savings without compromising functionality, making it a preferred choice for users. Its graphical interface makes network packet analysis less cumbersome compared to command-line alternatives. Moreover, Wireshark aids in in-depth analysis of TCAP messages, debugging of network data exchange issues, investigating network issues and locating lost IPs on the network, troubleshooting site-to-site VPN tunnels, identifying unusual activity in network traffic, tracking specific users' data for detection of client/server connectivity issues, aiding in networking and security education with real-time lab environments, capturing and analyzing network traffic for automation purposes, verifying protocol usage, troubleshooting firewall ruleset tests, monitoring traffic patterns, locating desired information within the network using powerful filters, identifying handshake issue algorithm compatibility problems with database servers and clients, diagnosing issues with VOIP phone systems causing dropped calls due to packet loss, capturing network traffic for system information management purposes, addressing ping scan DOS attacks on external locations and severe broadcast storms caused by corrupted NIC drivers on the main network. The versatility of Wireshark extends to various organizations where it is used for network design, testing, operation as well as helping technicians analyze network traffic effectively during troubleshooting at client sites.

Affordable Price: Many users appreciate the low cost of Wireshark, as it provides powerful network analysis capabilities without the need for expensive software. Several reviewers have stated that Wireshark offers a good value for its price.

Packet Analysis Capabilities: The ability to capture, log, and analyze packet data is highly valued by users. Many reviewers have mentioned that this feature allows for detailed troubleshooting and monitoring of network traffic in their feedback on Wireshark.

Real-time Network Visibility: Users find the real-time network data visibility provided by Wireshark to be invaluable. Several customers have mentioned that this feature enables them to monitor network activity promptly and identify any issues or anomalies with ease.

Confusing User Interface: Some users have found the user interface of Wireshark to be confusing, suggesting that it can be improved to make it more user-friendly and intuitive.

Steep Learning Curve: The software has a steep learning curve, with new users finding it overwhelming to see all the columns and colors. This can make it challenging for them to navigate and understand the software.

Lack of User-Friendliness: While acknowledging that Wireshark is not primarily designed for those who are not comfortable with this type of software, some users still mention the lack of a more user-friendly interface. They suggest enhancing the UI/UX to make it more intuitive and easier to use.

Users of Wireshark have made several recommendations based on their experience with the software. The most common recommendations include utilizing the free version, seeking help and documentation online, and exploring all features and capabilities.

Many users recommend using the free version of Wireshark as it is considered a great tool for networking systems and packet analysis. Users appreciate its stability and open-source nature.

To effectively use Wireshark, users advise seeking help and documentation online. They suggest following tutorials and reading the new user guide to understand how to navigate the software's features.

Users also recommend spending time exploring all the features and capabilities of Wireshark, although it may seem overwhelming at first. By doing so, users can fully utilize this powerful network sniffing tool, particularly on Linux systems.

Overall, users consider Wireshark an excellent network packet analyzer that caters to the needs of both network engineers and beginners in network engineering. However, some users caution obtaining security approval before using the software. While they acknowledge that Wireshark may provide more information than expected, they still regard it as a valuable tool for their networking needs.

Attribute Ratings

Reviews

(1-4 of 4)
Companies can't remove reviews or game the system. Here's why
Arnab Mukherjee | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
Incentivized
Wireshark is a tool used by our Network Systems and Security Teams to analyze incoming and outgoing traffic to troubleshoot Network Issues. The tool gives end-users the option to filter traffic on specific ports and protocols and provides the ability to select a specific packet and view the entire N/W stream the packet belongs to.
  • Analyzing Network Traffic
  • Verify is Specific Ports/Traffic is being blocked by N/W device Firewall
  • Provided Life Capture and also save a Packet Capture for further analysis
  • Provide Dashboard/Graphs to display N/W Traffic
  • Trigger Notifications based on certain Traffic received
Analyze Traffic across the Network. You can create your own filters with specific color codes to track the traffic of interest. The packet capture provides you all the details including the source, destination, protocol, ports and helps troubleshoot Network and Security related issues. This tool can also be used for Network and Security audits and Network Scans to monitor any rogue traffic.
  • Analyzing Network Traffic
  • Easy to use and is used by multiple departments Network, Security and Application
  • It is Easy to Use and Setup is very Easy
  • The data captured can be shared with different teams for further troubleshooting and working on a resolution to the issue.
  • Easy to Analyze the data, create own filters with easy to use expressions.
Wireshark is widely used and is the most popular packet analyzer available. It is a great debugging tool and easy to implement and use. It is Open Source and has a variety of options to analyze your network traffic.
SolarWinds NetFlow Traffic Analyzer (NTA), Splunk Enterprise
Chase Palmer, CISSP | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Wireshark is one of those tools that should be in every cyber security professional's toolbox. We use Wireshark for research and investigation. When reviewing a new software we will check the network traffic coming from applications to make sure that nothing strange is coming from or to the application.

We also set up various Capture the Flag challenges for recruiting purposes and use Wireshark to set up those challenges.
  • Network traffic inspection
  • Packet inspection
  • API testing/troubleshooting
  • Filters can be difficult to remember and formulate. A simple filter set or filter builder would be helpful.
I don't know of any other tool that works as well as Wireshark for packet capture an inspection. It's extremely easy to get up and running, and even with little to no knowledge of how to use the tool, you can be looking at all the traffic coming off a network interface.
  • Being able to see the network traffic happening on a device and from an application.
  • Being able to inspect the contents of packets.
  • We have a great tool to provide confidence in our application purchases.
  • We are able to inspect how our code is working when it is making network requests.
[Wireshark] is just the go-to application. It's the tool that is taught with in school and at trade conferences. We have not had a need to even look at other tools. It's free, it had a ton of functionality, and it just works without complaint.
Kenneth Hess | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We/I use Wireshark to capture and to analyze both wireless and wired network traffic. It is an absolutely required tool for any system administrator or network administrator. Our entire IT department uses it. Wireshark is both free and open source software, which, for what it does, saves us a lot of money. This graphical tool is easy to use and makes network packet analysis far less painful than if we had to rely just on the command line. Using Wireshark, we can analyze network traffic for further analysis ourselves or we can capture it and send it as a pcap file to a security consultant for further investigation. It is an essential part of our administrative toolbox.
  • Wireshark is easy to use and to collect network traffic with.
  • Wireshark color codes network packets based on which type of packet has been captured. This makes the analysis much quicker.
  • Wireshark has a lot of different filters that can be applied either during capture or during analysis to filter out uninteresting packets from the feed.
  • You can download and use a standalone (not installed) version to run on USB thumb drives or other external media in case you want to analyze a potentially compromised system in place.
  • Wireshark requires elevated privileges, which can either be bad or good depending on your perspective.
  • It has the standard disadvantage of capturing packets that might not reflect actual network traffic because the data is captured locally. Not a flaw of Wireshark, specifically, but of any locally run sniffing software.
  • It can be confusing for new users to see all the columns and colors. You can do a lot of customization but it takes some effort.
Wireshark is best suited to capturing and analyzing network traffic data. It is not an intrusion detection system (IDS), or a honeypot, or any real-time security tool. Offline analysis is where Wireshark shines. Take a capture using it or some other tool and load it into Wireshark for extensive analysis. Wireshark is great for forensic analysis of network traffic. You can find malformed packets, attack signatures, suspicious traffic, etc. Nothing gets by Wireshark.
  • Wireshark continues to have a positive effect/impact on our business because we don't necessarily have to hire an outside consultant to read our captures.
  • Wireshark, being free of charge, allows us to use a very advanced tool at no cost.
  • All packet analysis tools are non-trivial to learn and to use. Wireshark is perhaps the simplest of all that I've seen. It is mostly intuitive and well-designed.
I've looked at several over the years but Wireshark's no cost and advanced capabilities make it an easy choice for me. Wireshark's biggest advantage is its cost, which I've mentioned several times. It's significant in budget terms. I can't justify paying $1,000 for software that I can get for free. If I need something more advanced, I'd just pay a consultant, but they're likely to use Wireshark, so I'm not sure what I'd be paying for in the long run except a second opinion or another pair of eyes on the data.
Code42 (formerly CrashPlan), Dropbox, Adobe Photoshop
  • Wireshark is quick to use. Open it, and click Capture->Start to begin capturing packets.
  • Wireshark can load/ingest data from other sources such as tcpdump, so offline analysis is easy.
  • There are a lot of filters built into it, which are handy because you will capture thousands of packets very quickly. You'll need to use these filters.
  • I haven't found anything that's really difficult or cumbersome, but capturing wireless data can be challenging if your wireless network doesn't have some wireless connectivity.
I give Wireshark a 10 for usability because it is very usable. Just about anyone can capture packets within a few seconds of opening the program. The analysis is a science but as far as just using Wireshark; it's very easy.
Matthew Frederickson | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We use Wireshark to troubleshoot network problems - both wired and wireless. It's not uncommon to get a ticket from a user stating that the network is "slow". Since that is always less then helpful, we usually (after basic troubleshooting steps) start a Wireshark capture closest tot he endpoint with the issue. Invariably, we are always able to find the issue - whether it's endpoint or switch related - or even if it's something downstream. We've managed to train some of the IT staff in how to do a capture - so even if they don't understand what they are looking at, they are familiar with grapping a pcap file for our review.
  • Displays data (network captures) in a logical, clear way that enables you to easily see what is happening on the wire.
  • Provides expert help and color codes packet types so it's easy to quickly pick out different types of traffic.
  • Separates the data into three panes so you can get an overview, packet details, and see string data.
  • Can be a little intimidating right out of the box.
Wireshark is awesome for troubleshooting network issues. It gives you a direct view into what is happening on the wire. It takes the guesswork out of knowing what is happening on the wire - you can tell whether there are delays from web sites; file servers; voice issues. Yes - it is great for troubleshooting SIP traffic also.

It does not do massive file captures; it does not do a good job on massive packet capture files. If you are capturing traffic on a ten-gig or higher port, use tcpdump or some other mechanism to grab the data. Then use tshark (or one of the other included tools) to parse out what you need (time range, or specific type of traffic) to analyze inside wireshark.
  • Saves money by allowing me to see what's going on and gives me the ability to fix the issues myself. Otherwise, I would need to hire a consultant.
  • You would not expect a carpenter to build a house without a hammer. He has other tools that he uses, but the hammer is an important one. Well, Wireshark is like that for anyone responsible for maintaining or managing a network. It's one tool - one very important tool.
I'm not sure there are other products out there that can do all that Wireshark does for the price (free). Yes, there are commercial products that can do "more", but I haven't found the need to do anything "more" that I need to spend money on. It can generate reports; export data so you can generate your own graphs and reports; and allows you to perform baseline analysis on your network segments.
Return to navigation