Overview:
Author: Diyaa
Published date: August 6th, 2024
Last updated: August 6th, 2024
This document explains how to filter only the TCP handshake packets of every TCP streams in a PCAP file with Wireshark.
I used the answer in the Wireshark forums link referenced here 1 under References.
Filters:
IPv4 filter:
IPv6 filter:
Demonstration In Wireshark:
Note
I added a column to show the TCP stream index. This is not the default view in Wireshark.
I can only see the first 3 packets in each TCP stream. This can be useful when trying to troubleshoot TCP problems with Wireshark.
Related Notes:
- Link to Home-Page.