Wireshark settings for traffic analysis
People have their own favourite settings for wireshark. Here are my wireshark settings that I usually configure for traffic analysis.
1. Adding more fields for visibility
Go to Edit > Preferences, then add the following fields.
2. Disable relative seq number for TCP protocol
Go to Edit > Preferences > Protocols > TCP, then uncheck 'Relative sequence numbers'
3. Change time display format
4. Set Host info in HTTP header as column
: This is useful for HTTP analysis
4-1. start capturing
4-2. filter by http.request then pick the Host info and apply as column
4-3. now you get the host column as below
Designed by sketchbooks.co.kr / sketchbook5 board skin