Ask Your Question

Revision history [back]

To capture the traffic to and from a single IP, select the interface that contains the traffic of interest (if uncertain select them all) and then in the capture filter type:

host ip.of.interest

Note that if you're running on a typical wired network (switched) Wireshark will only be able to capture traffic between the machine you're capturing on and the IP of interest, traffic between that IP and others machines will NOT be captured.

If you're running on a Wireless network ,you might be able to capture traffic between other machines using "Monitor Mode", but this can be difficult to make work, especially using Windows as the capture machine.

There is an intro into Capture Setup on the Wiki, but it's quite technical as it's a technical task.