Reading PCAPs with Wireshark Statistics // Lesson 8 // Wireshark Tutorial

Поделиться
HTML-код
  • Опубликовано: 21 авг 2024
  • Protocol analysis is hard to do if we try to look at a pcap one packet at a time. In Wireshark we can use the Statistics feature to get a high level view of the conversations, protocols, and addressing in use in the traffic. Let's learn how to use this feature.
    Download the sample trace file here:
    www.cloudshark...
    (Select Export | Download to pull the trace down locally)
    Please smash the like button to let me know if you enjoy this content!
    == More On-Demand Training from Chris ==
    ▶Getting Started with Wireshark - bit.ly/udemywi...
    ▶Getting Started with Nmap - bit.ly/udemynmap
    == Live Wireshark Training ==
    ▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtual...
    == Private Wireshark Training ==
    Let's get in touch - packetpioneer....

Комментарии • 71

  • @efrensagun9397
    @efrensagun9397 2 года назад +16

    I love how this series is presented especially the duration of each lesson which only lasted below 9 mins, enough to cover the topic presented. Thanks for making these contents Chris. Super helpful.

  • @Renan_PS-zt8lm
    @Renan_PS-zt8lm 5 месяцев назад +1

    This is mindblowing, the most useful class for me by far.

  • @richardhyman6981
    @richardhyman6981 2 года назад +2

    Another excellent lesson! You really have taken something rather intimidating and broken it down into bite-size, real world examples we can cut our teeth on! Thank you!

    • @ChrisGreer
      @ChrisGreer  2 года назад +1

      Thanks for the comment again Richard. Really glad you like the content

  • @workflowinmind
    @workflowinmind Год назад

    Man I've tried countless times to make sense of Wireshark (for years), I always was completely lost (although I'm supposedly quite technical)
    Thanks to this series it finally clicked! Thanks a lot

  • @outerheaven01
    @outerheaven01 3 года назад +1

    I already use this as you have mentioned it in your previous content. This is super helpful. First thing I do when I open a trace. I'm not a network engineer but it helps me understand so much. Keep up the good content. Thanks Chris!

  • @Funnybone_FB
    @Funnybone_FB 2 года назад +3

    Cannot thank you enough for this, Chris. I am so grateful for these lessons and tutorials.

  • @edsonrocks
    @edsonrocks 3 года назад +4

    Brilliant Chris, as always.
    You make it look so easy 😅
    Thank you

  • @user-ee7nw2kn6u
    @user-ee7nw2kn6u 5 месяцев назад +1

    thank you chris you make wireshark very easy and network analysis easy

  • @arghosinha1424
    @arghosinha1424 5 месяцев назад

    9m of pure Wireshark knowledge. 🤟

    • @ChrisGreer
      @ChrisGreer  5 месяцев назад

      Next time it will be 10 mins 😆

  • @NanookFieryArcticSkyy
    @NanookFieryArcticSkyy Год назад

    Very good I learn tools on each class. WS users are empowered when they know how to use a tool.

  • @breakingbisley
    @breakingbisley 2 года назад +8

    Hey Chris, thanks for the hard work, and lessons. I imagine this takes a lot of your time, I myself appreciate this. These lessons and the other videos are helping me understand networking on a higher concept (As I work with Palos and Fortigates), in which is helping me troubleshoot issues.

  • @IchbinGigio
    @IchbinGigio 2 года назад +1

    Man I've been learning so much with your videos.
    Thank you for this beautiful act of sharing all of this 🙏🏻👍🏻

  • @RicardoDiaz21129
    @RicardoDiaz21129 9 месяцев назад

    As always, thank you so much Chris. Have learned so much from your videos!!

  • @soliid_snake_xx4113
    @soliid_snake_xx4113 Год назад

    Thank you Chris! Definitely subscribing. You DA MAN

  • @Black_Swan68761
    @Black_Swan68761 2 года назад

    Superb!! you are awesome. Amazing, another trick i learnt from this video.
    Millions of Thanks to you.

  • @user-zc4nx5td2j
    @user-zc4nx5td2j 6 месяцев назад

    Thank you so much-just leaning this and needed a quick overview of p-cap and you, jus tin this video, brought all the obscurity I have learned into something I get- I GOT IT!!! ( I think haha). Thank yo so much!!!

  • @avihskshetrii
    @avihskshetrii Год назад +1

    Finally the use of statistics ...easy to find out the fishy activities

  • @kosmonautofficial296
    @kosmonautofficial296 2 года назад

    Great video Chris! These statistics recently helped me solve a problem, thank you!

  • @nms9352
    @nms9352 3 года назад +1

    Thanks, Chris! - as always, super helpful content and very well presented!

  • @maxwellchessdotcom6952
    @maxwellchessdotcom6952 2 года назад

    Good stuff!

  • @kevinmckee6218
    @kevinmckee6218 4 месяца назад

    awesome video.

  • @ptyspawnbinbash
    @ptyspawnbinbash 2 года назад +1

    Awesome videos and series, loving it! Thanks a lot for the effort you put into these videos. :)

  • @wagnerj01
    @wagnerj01 Год назад

    As always, great job on this video.
    Thanks

  • @prasadshinde8271
    @prasadshinde8271 3 года назад

    This is really helpful chris, Thanks for creating the videos.

  • @mariotpc
    @mariotpc Год назад

    Thanks Chris ! Excellent lesson...!

    • @ChrisGreer
      @ChrisGreer  Год назад

      You are welcome! Thanks for watching.

  • @aeonarchery4539
    @aeonarchery4539 Год назад

    awsome thing to learn to become Packet dhakkan :P

  • @ahmadmaherchemohdadib911
    @ahmadmaherchemohdadib911 3 года назад

    Thanks Chris! Love it. Before this, I used manually count! Hahaha..forgot Wireshark has features of statistics :)

    • @ChrisGreer
      @ChrisGreer  3 года назад

      don't feel bad... I did too! Until someone showed me how to use Statistics better. Thanks for the comment and for stopping by the channel!

  • @amirahmed1404
    @amirahmed1404 3 года назад

    This is helpful Chris. Thanks a lot.

  • @RobertBesmonte
    @RobertBesmonte 2 года назад

    Thank you, Chris! I appreciate this kind of tutorials hope to see more from you so that we could be on your level ;)

    • @ChrisGreer
      @ChrisGreer  2 года назад

      Thanks for the comment Robert!

  • @sri9277
    @sri9277 3 года назад

    Your explanation is super ❤️

  • @user-qb3co2jb9z
    @user-qb3co2jb9z 2 года назад

    Thank you a lot for the lessons!!

  • @romansovetskikh7902
    @romansovetskikh7902 2 года назад

    Suitale set of lessons. Many thanks.

  • @RajkumarNayak
    @RajkumarNayak 3 года назад

    Great stuff as always..

  • @domagoj19zg
    @domagoj19zg 3 года назад

    thanks for creating these videos :)

  • @jaybay711
    @jaybay711 11 месяцев назад

    Great Video

  • @sandeepm625
    @sandeepm625 2 года назад

    nice content. very helpful

  • @jnelly3426
    @jnelly3426 Год назад

    Good Stuff

  • @judahtunes2245
    @judahtunes2245 Год назад

    Thanks Dude

  • @Kennomie
    @Kennomie 2 года назад

    nice explanation, keep it up please, thank you!

  • @vyasG
    @vyasG 2 года назад

    Thank you so much for this video. Great content, and very useful. This series is too good, and your teaching style is one of the best - Easy to follow and you keep us focused! Appreciate your time and effort in doing this.
    I have a question - Regarding the values of each column, I see they are aligned to left, right or centre. Is it possible to change this, like make all the column values aligned to the centre?

    • @ChrisGreer
      @ChrisGreer  2 года назад +1

      Hello Vyas, Thanks for the comment. For centering the columns... I have always just done it one column at a time, not all of them. I'll have to dig to see if there is a way we can do all of them. Good question!

  • @HomeDesign_Austin
    @HomeDesign_Austin 8 месяцев назад

    great

  • @ItsBigTexYall
    @ItsBigTexYall 2 года назад

    Chris, I may be nitpicking Wireshark a little much here, but at 2:03, you're looking at Layer 2 conversations...why does Wireshark refer to that as Packets rather than Frames?

  • @majiddehbi9186
    @majiddehbi9186 2 года назад

    hi chris i' m brand new here i m from north afric i take my CCNA very soon so I hope this will be benefic for me thx for u re time

    • @ChrisGreer
      @ChrisGreer  2 года назад

      Hello Majid! I hope you get that CCNA!

    • @majiddehbi9186
      @majiddehbi9186 2 года назад

      @@ChrisGreer thx Chris and God bless u

  • @yourtube12345
    @yourtube12345 Год назад

    can pls explain tshark as well

  • @raomohsin7617
    @raomohsin7617 Год назад +1

    Hi Chris,
    Could you please tell me what are these files
    1.libnl-3.so....
    2.libnl-genl.so.....
    3.libnl-route.so....
    I'm getting error when I run Wireshark.
    libnl-route version information not found...
    Wireshark doesn't capture n/w traffic.

  • @saianoop9515
    @saianoop9515 10 месяцев назад

    Hey there,
    I am currently working on a project for a class that requires using Wireshark to analyze a pcap file. I am looking at 5 specific IP addresses and need to classify the devices as Apple, Android, or Window as well as if it's a DNS server, router, printer, or modem. Is there any tricks to accomplish this? I am new to Wireshark.

  • @dopy8418
    @dopy8418 3 года назад

    Graphs next ?

  • @danielmitroff1201
    @danielmitroff1201 2 года назад

    Hello Chris! A have a question. For example, we have big pcap file with a lot of source IP which communicates with some server in our infrastructure. How can i get statistics about packet per second for each src Ip. Yes, i can take some Ip and go to input/output Graph and check it here, but if we have hundreds or thousands of ips, it problematic to do that.

    • @ChrisGreer
      @ChrisGreer  2 года назад +1

      Hi Daniel! So if you want to do this within the Wireshark GUI - you can go to Statistics // Conversations // IP. On the far right is Bits/s A->B and Bits/s B->A. That shows overall throughput for that conversation. We can also do this on the command line with tshark - go to your command line and use "tshark -q -z conv,ip -r input.pcap" without the quotes. That should generate the same stats for you, but on the command line.

    • @danielmitroff1201
      @danielmitroff1201 2 года назад

      @@ChrisGreer Thanx, but you are talking about Bits/s , When I need Packets Per second (pps)

  • @aaronallen976
    @aaronallen976 2 года назад

    who is X.2.2?