Wireshark Filter Generator
Build accurate Wireshark display filters for packet analysis without memorizing complex syntax. Combine fields, operators, protocols, IPs, ports, text matches, TCP flags, and expert troubleshooting conditions.
Filter Builder
Create one or more filter conditions and combine them with AND / OR.
Predefined Wireshark Filters
Click any example to load it into the output box.
Common Troubleshooting Recipes
Capture Filter Reference
Capture filters are applied before packet capture and use BPF/libpcap syntax. Do not paste these into the Wireshark display-filter box.
| Purpose | Capture Filter |
|---|---|
| Host traffic | host 192.168.1.10 |
| Source host | src host 192.168.1.10 |
| Destination host | dst host 192.168.1.20 |
| TCP port 443 | tcp port 443 |
| DNS traffic | udp port 53 or tcp port 53 |
| Subnet traffic | net 10.0.0.0/24 |
| Exclude SSH | not tcp port 22 |
| HTTP/HTTPS | tcp port 80 or tcp port 443 |
How to Use This Tool
Choose a category
Select Network, TCP, DNS, TLS, HTTP, ICMP, IPv6, Security, or another analysis area.
Select the field
Pick a common Wireshark field such as ip.addr, tcp.port, dns.qry.name, or tcp.analysis.retransmission.
Set operator and value
Use equals, contains, regex, comparison operators, set membership, or simply test whether a field exists.
Add more conditions
Combine conditions with AND or OR. Parentheses are added automatically where needed.
Copy into Wireshark
Paste the generated expression into Wireshark’s display-filter bar and press Enter.
Narrow the packet set
Use the predefined troubleshooting filters for resets, retransmissions, duplicate ACKs, DNS errors, SYNs, and TLS alerts.
Display-filter syntax essentials
== equality, != inequality, && AND, || OR, ! NOT, contains substring/element search, and matches regular-expression matching.
Examples: ip.addr == 192.168.1.10, tcp.port == 443 && ip.src == 10.0.0.5, http.host contains "example".
Useful analysis workflow
1. Identify the client/server IPs. 2. Filter the conversation. 3. Check SYN/SYN-ACK/ACK. 4. Look for resets and retransmissions. 5. Inspect DNS and TLS when applicable. 6. Follow the TCP or HTTP stream for application-level context.
Privacy and safe use
This plugin builds filter text in the browser and does not require packet captures to be uploaded. Packet captures can contain credentials, cookies, hostnames, IP addresses, user data, and other sensitive information. Analyze captures only when authorized and protect PCAP/PCAPNG files appropriately.
Your feedback matters