Skip to main content
TrustRadius
Wireshark

Wireshark

Overview

What is Wireshark?

Wireshark is a free and open source network troubleshooting tool.

Read more

Learn from top reviewers

Return to navigation

Pricing

View all pricing

Wireshark

Free

On Premise

Entry-level set up fee?

  • No setup fee

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services
Return to navigation

Product Demos

Local and Remote Sniffing with Wireshark

YouTube

Wireshark demo (simple http)

YouTube

Saving Files From Wireshark

YouTube

Brim Demo

YouTube

How to Use Wireshark's Follow TCP Stream Feature

YouTube

Wireshark SIP Capture

YouTube
Return to navigation

Product Details

What is Wireshark?

Wireshark is a free and open source network troubleshooting tool.

Wireshark Technical Details

Deployment TypesOn-premise
Operating SystemsWindows, Linux, Mac
Mobile ApplicationNo

Frequently Asked Questions

Wireshark is a free and open source network troubleshooting tool.

Wireshark starts at $0.

Reviewers rate Usability and Support Rating highest, with a score of 10.

The most common users of Wireshark are from Mid-sized Companies (51-1,000 employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews From Top Reviewers

(1-5 of 32)

Powerful, Easy to use, Exactly what you need!

Rating: 10 out of 10
September 13, 2019
Vetted Review
Verified User
Wireshark
5 years of experience
I use it as a systems information manager to capture traffic on the network and analyze the packets for various reasons. I have used it to find a ping scan from a wireless network that was DOS'ing an external location, and also have used it to pinpoint a system with a corrupted NIC driver that was causing a severe broadcast storm on our main network.
  • Packet capturing
  • Packet analysis
  • Traffic monitoring and reporting
Cons
  • It is beginner-friendly as far as installation, but it could use a tutorial.
  • Perhaps there is a way to do this already, but I haven't yet seen it. It would be nice if it could be integrated with a network package that could detect network anomalies, fire up an automated packet analysis, and send a report to an administrator.
It is invaluable for capturing and analyzing network traffic and identifying issues with devices that are either malfunctioning, or possibly even set up as rogue devices on a network. Using the data from a packet analysis combined with logs and MAC tables from various network devices, it can be used to find specifically where a device might be located. It's not a "set it and forget it" application, but it is well suited for on-the-spot analysis.

Simple Easy Open Source Packet Analyzer

Rating: 9 out of 10
July 27, 2021
AM
Vetted Review
Verified User
Wireshark
10 years of experience
Wireshark is a tool used by our Network Systems and Security Teams to analyze incoming and outgoing traffic to troubleshoot Network Issues. The tool gives end-users the option to filter traffic on specific ports and protocols and provides the ability to select a specific packet and view the entire N/W stream the packet belongs to.
  • Analyzing Network Traffic
  • Verify is Specific Ports/Traffic is being blocked by N/W device Firewall
  • Provided Life Capture and also save a Packet Capture for further analysis
Cons
  • Provide Dashboard/Graphs to display N/W Traffic
  • Trigger Notifications based on certain Traffic received
Analyze Traffic across the Network. You can create your own filters with specific color codes to track the traffic of interest. The packet capture provides you all the details including the source, destination, protocol, ports and helps troubleshoot Network and Security related issues. This tool can also be used for Network and Security audits and Network Scans to monitor any rogue traffic.

Wireshark is free for those who like to snoop without limitations

Rating: 10 out of 10
September 25, 2018
KH
Vetted Review
Verified User
Wireshark
12 years of experience
We/I use Wireshark to capture and to analyze both wireless and wired network traffic. It is an absolutely required tool for any system administrator or network administrator. Our entire IT department uses it. Wireshark is both free and open source software, which, for what it does, saves us a lot of money. This graphical tool is easy to use and makes network packet analysis far less painful than if we had to rely just on the command line. Using Wireshark, we can analyze network traffic for further analysis ourselves or we can capture it and send it as a pcap file to a security consultant for further investigation. It is an essential part of our administrative toolbox.
  • Wireshark is easy to use and to collect network traffic with.
  • Wireshark color codes network packets based on which type of packet has been captured. This makes the analysis much quicker.
  • Wireshark has a lot of different filters that can be applied either during capture or during analysis to filter out uninteresting packets from the feed.
  • You can download and use a standalone (not installed) version to run on USB thumb drives or other external media in case you want to analyze a potentially compromised system in place.
Cons
  • Wireshark requires elevated privileges, which can either be bad or good depending on your perspective.
  • It has the standard disadvantage of capturing packets that might not reflect actual network traffic because the data is captured locally. Not a flaw of Wireshark, specifically, but of any locally run sniffing software.
  • It can be confusing for new users to see all the columns and colors. You can do a lot of customization but it takes some effort.
Wireshark is best suited to capturing and analyzing network traffic data. It is not an intrusion detection system (IDS), or a honeypot, or any real-time security tool. Offline analysis is where Wireshark shines. Take a capture using it or some other tool and load it into Wireshark for extensive analysis. Wireshark is great for forensic analysis of network traffic. You can find malformed packets, attack signatures, suspicious traffic, etc. Nothing gets by Wireshark.

A "dump" a day is a wonderful thing! A day is not complete without having used Wireshark.

Rating: 10 out of 10
November 29, 2017
AR
Vetted Review
Verified User
Wireshark
13 years of experience
Troubleshooting of reported issues and verification of facts (i.e. that a certain protocol is being used).
  • Very powerful and easy to use (once you understand the basic interface).
  • Free and easy to install.
  • Flexible and can be used in many different scenarios.
Cons
  • Bring back the Legacy option!
  • Improve the ease of use for some advanced functionality (such as decoding of video into H.264 or seeing the encryption type being used).
  • Sometimes the GUI can become non-responsive when using RDP.
Anytime you want to see what is happening between point A and point B on the network.
Obviously, it can't be used when trying to capture communication between one socket and another socket on the same machine.

To Wireshark or not

Rating: 9 out of 10
October 31, 2022
BG
Vetted Review
Verified User
Wireshark
14 years of experience
We use Wireshark in a multitude of ways. First, we troubleshoot connectivity issues with it, second, we use it for Firewall ruleset tests and third we use it to monitor odd traffic patterns. We find it most helpful when setting up a new product and a vendor is blaming something on our firewall and we can then show them the logs that the traffic is getting through to their side but no response.
  • Packet sniffing
  • Traffic pattern recreation
  • Traffic monitoring
Cons
  • More point and click
  • Images are difficult to decode
When I want to see what type of traffic is leaving a workstation, Wireshark is second to none. However, if I want to see images, it then becomes much more difficult to render the images.
Return to navigation