• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 233
  • Last Modified:

How can I export parts of a very large (2 hour) Wireshark capure?

I have an extremely large (2 hours) Wireshark capture, and I wish to export only the traffic from (2) of the devices that were talking on the network.  I have gotten the correct filter applied

(ETHERNET [all protocols] between IP 10.10.100.1 and 10.10.100.2)

And it displays the way that I want to export it....but I cannot figure out how to get it to export / save as / etc...with ONLY these filtered objects in the capture output.

Can anyone help?
0
jkeegan123
Asked:
jkeegan123
  • 2
1 Solution
 
jkeegan123Author Commented:
I figured this out myself...after you have the filter applied, you have to go to FILE --> SAVE AS, and in the SAVE AS window, change the radio button from ALL PACKETS to SELECTED PACKETS.
0
 
jkeegan123Author Commented:
I nailed it.
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now