官术网_书友最值得收藏!

Saving the filtered traffic

During or after completing an analysis, you will want to save a set of filtered packets into a new capture file. Saving a filtered subset of the bulk capture data and opening the new, smaller file in Wireshark is helpful to reduce the distracting background noise packets displayed when clearing display filters, working with Conversations windows, and so on during your analysis. Finally, upon completing your analysis, you will want a filtered capture file that represents the analysis evidence and conclusion and can be quickly loaded for review at a later time.

Use the Export Specified Packets option in the File menu to save a new capture file consisting of just your filtered packets. Navigate to the desired directory; enter a filename (Wireshark will provide the appropriate filename extension); make the appropriate selections to save all the Displayed packets, Marked packets, and/or to Remove Ignored packets; and then click on Save. Remember to save the complete capture using the Save As option in the File menu as well, because you may need this file again.

The following screenshot illustrates a typical Export Specified Packets window and its selections:

主站蜘蛛池模板: 揭西县| 那曲县| 肇源县| 天等县| 芜湖市| 台东县| 米易县| 元阳县| 乌海市| 汶川县| 皋兰县| 巢湖市| 平利县| 武安市| 金乡县| 陵水| 昌邑市| 大邑县| 祁阳县| 马尔康县| 昭苏县| 霍州市| 和静县| 陵川县| 浮山县| 陇南市| 黄陵县| 阜康市| 锦屏县| 晋江市| 洛宁县| 谷城县| 桂东县| 科尔| 曲松县| 确山县| 乌拉特中旗| 子长县| 东宁县| 封开县| 蛟河市|