Avatar of Goraps
GorapsFlag for Canada asked on

WireShark - Packet capture on a single IP

I have a laptop with wireshark 1.10.1 running in my server room, attached to the switch where the system I want to packet sniff. How do I setup WireShark just to sniff what is coming out of 1 single IP address? Please advise.

Regards,

GoRaps
Network AnalysisTCP/IPNetwork Management

Avatar of undefined
Last Comment
Darr247

8/22/2022 - Mon
dipopo

Your question sounds odd "WireShark just to sniff what is coming out of 1 single IP address? Please advise"

I'm guessing you meant 1 interface/port, which wireshark can do and filter for your specific IP. Be sure to install winPcap.

Also have you set-up a span port to mirror everything to the port you are connected to?

http://www.cisco.com/en/US/docs/switches/lan/catalyst2940/software/release/12.1_19_ea1/configuration/guide/swspan.html
ASKER
Goraps

Sorry yes... I want to capture what is coming out of 1 interface. By default is it capturing all DATA?
dipopo

Yes, all data will be captured as winPcap will put the interface into promiscuous mode and accept all. You can then filter for specific IP,protocols or other.
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23
ASKER
Goraps

Is that data easily readable or do I need something else make this happen?
dipopo

Its easily readily human readable.
Qlemo

You should have a capture filter example in WireShark for filtering for a specific IP address, so it should be very easy for you to set it up (the example is called "IP address", the capture filter expression is "host 192.168.141.22" - replace the IP address with the one you want to monitor).
In WireShark you need to differ between display filters  - those can be set on the fly while capturing, and have a different syntax, but do not restrict the data captured, only what you see at the moment -  and capture filters, which will exclude anything from being captured which does not fit into the filter, reducing the amount of data.
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
ASKER CERTIFIED SOLUTION
Darr247

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question