Selecting specified packets

After you have filtered a capture, you may want to export a portion of the capture. With Wireshark, you can be very specific in what you select to export. Let's step through an example.

Return to the bigFlows.pcap capture and enter tcp.stream eq 946 in the display filter. Once you have run the filter, you are ready to preserve this subset. In this case, we will go to the File menu choice, and then Export Specified Packets. Once open, you will see that you have several ways to export file components, as shown in the following screenshot:

Export Specified Packets

Near the bottom of the dialog box, you will see a header ...

Get Learn Wireshark - Fundamentals of Wireshark now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.