Skip to main content
TrustRadius
Wireshark

Wireshark

Overview

What is Wireshark?

Wireshark is a free and open source network troubleshooting tool.

Read more
Recent Reviews

TrustRadius Insights

Wireshark, a widely utilized network traffic analysis tool, has proven to be invaluable for various user experiences and use cases. Cyber …
Continue reading

Indispensable tool

9 out of 10
October 31, 2022
Incentivized
Its port scans help you find the problem quickly. Recently I had to analyze a company because there was so much traffic on the network.
Continue reading

To Wireshark or not

9 out of 10
October 31, 2022
We use Wireshark in a multitude of ways. First, we troubleshoot connectivity issues with it, second, we use it for Firewall ruleset tests …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Return to navigation

Pricing

View all pricing

Wireshark

Free

On Premise

Entry-level set up fee?

  • No setup fee

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services
Return to navigation

Product Demos

Local and Remote Sniffing with Wireshark

YouTube

Wireshark demo (simple http)

YouTube

Saving Files From Wireshark

YouTube

Brim Demo

YouTube

How to Use Wireshark's Follow TCP Stream Feature

YouTube

Wireshark SIP Capture

YouTube
Return to navigation

Product Details

What is Wireshark?

Wireshark is a free and open source network troubleshooting tool.

Wireshark Technical Details

Deployment TypesOn-premise
Operating SystemsWindows, Linux, Mac
Mobile ApplicationNo

Frequently Asked Questions

Wireshark is a free and open source network troubleshooting tool.

Wireshark starts at $0.

Reviewers rate Support Rating highest, with a score of 10.

The most common users of Wireshark are from Mid-sized Companies (51-1,000 employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(135)

Community Insights

TrustRadius Insights are summaries of user sentiment data from TrustRadius reviews and, when necessary, 3rd-party data sources. Have feedback on this content? Let us know!

Wireshark, a widely utilized network traffic analysis tool, has proven to be invaluable for various user experiences and use cases. Cyber security professionals rely on Wireshark for research and investigation, allowing them to check network traffic from applications and ensure there are no abnormalities. The software's versatility is demonstrated by its utilization in setting up Capture the Flag challenges, making it an engaging tool for recruiting purposes. Additionally, Wireshark is essential for monitoring network traffic and troubleshooting network-related issues, saving time and effort in problem-solving. It enables system administrators and network administrators to dissect network packets in detail, extract relevant network information, and quickly identify and resolve network problems. The software's free and open-source nature provides cost savings without compromising functionality, making it a preferred choice for users. Its graphical interface makes network packet analysis less cumbersome compared to command-line alternatives. Moreover, Wireshark aids in in-depth analysis of TCAP messages, debugging of network data exchange issues, investigating network issues and locating lost IPs on the network, troubleshooting site-to-site VPN tunnels, identifying unusual activity in network traffic, tracking specific users' data for detection of client/server connectivity issues, aiding in networking and security education with real-time lab environments, capturing and analyzing network traffic for automation purposes, verifying protocol usage, troubleshooting firewall ruleset tests, monitoring traffic patterns, locating desired information within the network using powerful filters, identifying handshake issue algorithm compatibility problems with database servers and clients, diagnosing issues with VOIP phone systems causing dropped calls due to packet loss, capturing network traffic for system information management purposes, addressing ping scan DOS attacks on external locations and severe broadcast storms caused by corrupted NIC drivers on the main network. The versatility of Wireshark extends to various organizations where it is used for network design, testing, operation as well as helping technicians analyze network traffic effectively during troubleshooting at client sites.

Affordable Price: Many users appreciate the low cost of Wireshark, as it provides powerful network analysis capabilities without the need for expensive software. Several reviewers have stated that Wireshark offers a good value for its price.

Packet Analysis Capabilities: The ability to capture, log, and analyze packet data is highly valued by users. Many reviewers have mentioned that this feature allows for detailed troubleshooting and monitoring of network traffic in their feedback on Wireshark.

Real-time Network Visibility: Users find the real-time network data visibility provided by Wireshark to be invaluable. Several customers have mentioned that this feature enables them to monitor network activity promptly and identify any issues or anomalies with ease.

Confusing User Interface: Some users have found the user interface of Wireshark to be confusing, suggesting that it can be improved to make it more user-friendly and intuitive.

Steep Learning Curve: The software has a steep learning curve, with new users finding it overwhelming to see all the columns and colors. This can make it challenging for them to navigate and understand the software.

Lack of User-Friendliness: While acknowledging that Wireshark is not primarily designed for those who are not comfortable with this type of software, some users still mention the lack of a more user-friendly interface. They suggest enhancing the UI/UX to make it more intuitive and easier to use.

Users of Wireshark have made several recommendations based on their experience with the software. The most common recommendations include utilizing the free version, seeking help and documentation online, and exploring all features and capabilities.

Many users recommend using the free version of Wireshark as it is considered a great tool for networking systems and packet analysis. Users appreciate its stability and open-source nature.

To effectively use Wireshark, users advise seeking help and documentation online. They suggest following tutorials and reading the new user guide to understand how to navigate the software's features.

Users also recommend spending time exploring all the features and capabilities of Wireshark, although it may seem overwhelming at first. By doing so, users can fully utilize this powerful network sniffing tool, particularly on Linux systems.

Overall, users consider Wireshark an excellent network packet analyzer that caters to the needs of both network engineers and beginners in network engineering. However, some users caution obtaining security approval before using the software. While they acknowledge that Wireshark may provide more information than expected, they still regard it as a valuable tool for their networking needs.

Attribute Ratings

Reviews

(1-25 of 29)
Companies can't remove reviews or game the system. Here's why
Kaveen Eashwarage | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
  • Possibility to analyze packets from various interfaces (LAN,Wifi,BT,USB).
  • Ability to integrate with GNS3 easily.
  • Its a free tool and available on all platforms.
  • Provide comprehension analysis on communication protocols.
  • Learning curve is a little steep.
  • Encrypted network traffic read is a a struggle.
  • User interface can be developed
Score 10 out of 10
Vetted Review
Verified User
Incentivized
  • Ease of capturing and analyzing incoming and outgoing network traffic.
  • It allows offline analysis of inspected and captured packages.
  • Excellent and friendly interface.
  • Large community with great support and advanced feature tips.
  • Windows compatible.
  • It is bad for parsing very large packets.
  • It takes time and patience to analyze all packages.
Swapnil Madiwale | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
  • Great UI & Command Line Tools
  • Packet capture feature is very good
  • It is open source which is the best thing in a tool like Wireshark
  • A little bit of intrusion detection feature would help
  • Other than that, I don't think it lacks anything
  • Perfect little tool
Vrej Anbarsoun | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
Incentivized
  • Captures network traffic
  • Categorizes network traffic based on many different categories
  • Offers numerous filtering options to reduce unnecessary clutter
  • Perhaps Wireshark could offer more regular updates/upgrades.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
  • Easy to use GUI
  • Packet capturing is on point
  • Rock solid stable
  • A lot of functionality
  • Great support and maintenance
  • Large PCAP files load too long
  • Manual query syntax is hard to remember
  • Some features are hard to find
Score 10 out of 10
Vetted Review
Verified User
Incentivized
  • Realtime network data visibility
  • TCP/IP Packet inspection
  • Wired/Wireless network troubleshooting
  • Fairly straightforward, but not the simplest program to use
  • You do bounce around between windows and clicking various buttons for starting and stopping. While the interface is good, it could be streamlined somewhat
Arnab Mukherjee | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
Incentivized
  • Analyzing Network Traffic
  • Verify is Specific Ports/Traffic is being blocked by N/W device Firewall
  • Provided Life Capture and also save a Packet Capture for further analysis
  • Provide Dashboard/Graphs to display N/W Traffic
  • Trigger Notifications based on certain Traffic received
Mauro Biefeni | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
  • Capture Network Traffic - This really is the essential functionality of Wireshark as without consistent data capture there is nothing to analyze
  • Filtering - We need to often filter for specific data that we are looking for.
  • Live Capture as well as offline analysis - This gives us the flexibility to do what we need to do when we need to do it.
  • A more user-friendly interface would be nice, but then again it is not really designed for those who are not quite comfortable with this type of software.
  • Changes to functionality on updates - this can sometimes happen unexpectedly and can be an annoyance.
  • More powerful data processing would be welcomed
Drew Harrison | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
  • Captures all kinds of packet data in network traffic
  • Save & restore captured packed data
  • Show errors and issues in levels below the HTTP protocol
  • Can't modify or manipulate things/data on the network (only records data)
  • A better interface would be nice - it's functional as-is, but it could use some polish
Score 10 out of 10
Vetted Review
Verified User
Incentivized
  • Packet capturing
  • Packet analysis
  • Traffic monitoring and reporting
  • It is beginner-friendly as far as installation, but it could use a tutorial.
  • Perhaps there is a way to do this already, but I haven't yet seen it. It would be nice if it could be integrated with a network package that could detect network anomalies, fire up an automated packet analysis, and send a report to an administrator.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
  • EXTENSIVE detail
  • Easy to run, even for non-networking individuals. Makes it so they can run a packet capture on their machine and send to the network team for analysis.
  • Lowcost
  • Packet capture files get extremely large, extremely quickly.
  • Sifting through packet capture can be arduous at times.
  • Sometimes it feels almost "too in-depth" and can be overwhelming to look at. Hard to know where to start looking.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
  • Wireshark is easy to use, the user can customize the display layout of the packet based on the user's own interests to only highlight the network layers and parameters being cared about.
  • There are plenty of integrated/embedded tools inside Wireshark can be used to perform deep analysis of the different type of network issues.
  • Filter and search functionality are so powerful which can be helpful for network issue troubleshooting.
  • It's better to integrate some APIs to the high-level users allowing them to design and program their own deep analysis functions to support the work.
  • it's better to optimize the algorithm processor a little bit as I will normally have trouble to open a big size packet capture larger than 3GB, the computer will become very slow and take a very long time to open the file and perform any analysis.
Jaspreet Singh | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
  • Light-weight software - Does not require high end specifications; also runs smoothly on Legacy systems
  • Filter function - Lets you filter you packets from thousands to tens so as to find your target much easily
  • Simultaneous capturing on all the network adapters - You can capture packets from all the Network Interface Cards (NIC's) at once.
  • GUI of the software can improve a bit; like some more animations can be added to make it more user friendly
  • Some more learning resources can be officially added; like filter query function is much advanced, but everyone does not know how to efficiently use it
  • Themes can also be provided to users so that people who work on this software for hours can have a new experience by changing the colors of the software
February 11, 2019

Wireshark is Solid :-)

NAKIA EPLEY | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
Incentivized
  • Wireshark is SO easy to use! At very first glance, it can be a little overwhelming but after about 2 or 3 times of being walked through instruction, the ease of use makes the packet capture process easy to understand.
  • The *(TCP/UDP/HTTP, etc) filters make things very clear, and hides the information that you do not need at the moment. Following the TCP stream is laid out easily to be able to view the intrusion.
  • Integrates very well into the virtual environments as well as real-time. It acts on the virtual environment just as if it were on my physical computer.
  • There are a lot of troubleshooting features, but at this point in my program, I have not really run into anything too terribly negative to say about Wireshark.
Kenneth Hess | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
  • Wireshark is easy to use and to collect network traffic with.
  • Wireshark color codes network packets based on which type of packet has been captured. This makes the analysis much quicker.
  • Wireshark has a lot of different filters that can be applied either during capture or during analysis to filter out uninteresting packets from the feed.
  • You can download and use a standalone (not installed) version to run on USB thumb drives or other external media in case you want to analyze a potentially compromised system in place.
  • Wireshark requires elevated privileges, which can either be bad or good depending on your perspective.
  • It has the standard disadvantage of capturing packets that might not reflect actual network traffic because the data is captured locally. Not a flaw of Wireshark, specifically, but of any locally run sniffing software.
  • It can be confusing for new users to see all the columns and colors. You can do a lot of customization but it takes some effort.
Return to navigation