Try our new research platform with insights from 80,000+ expert users
Chad Nel - PeerSpot reviewer
Senior System Administrator at YGtech
Real User
It's a powerful tool that lets you see everything in your network
Pros and Cons
  • "Wireshark has a lot of features. It's a powerful tool if you're familiar with it. You can see everything on the network with it."
  • "The average person would probably find Wireshark hard to use. When I first installed it, I was overwhelmed by all the data it was shooting out. It doesn't make sense until you start doing some research and figure out what everything means. It isn't the most user-friendly tool. It just provides so much information."

What is our primary use case?

Wireshark is a tool for ARP scanning. I started using Wireshark back when I had a YouTube channel. It was mostly a security channel to show people how easily you can get hacked and how to hack. I was doing some research for my videos. I didn't know much about security, but I was interested in it, and Wireshark was one of the software solutions that kept popping up.

I watched some videos on how to use it and incorporated that into some of my videos. When I discovered something funny on my network a couple of years later, I decided to reinstall Wireshark to run some scans and found the culprit.

 It's all on-premises. Here in South Africa, a couple of companies have migrated to the cloud, but that's quite expensive for many of them. It's much easier and cheaper to buy a server and host everything locally. The only thing they keep in the cloud is email because on-premise email is just horrible. Most of my clients are on-premises. One or two has Azure or something like that.

What is most valuable?

Wireshark has a lot of features. It's a powerful tool if you're familiar with it. You can see everything on the network with it.

What needs improvement?

The average person would probably find Wireshark hard to use. When I first installed it, I was overwhelmed by all the data it was shooting out. It doesn't make sense until you start doing some research and figure out what everything means. It isn't the most user-friendly tool. It just provides so much information. 

I'm probably not familiar with it enough to say what features it's missing, but it could be a bit more accessible to the average system administrator having issues on their network so they can pull it out and run some scans.

What do I think about the stability of the solution?

I rate Wireshark eight out of 10 for stability.

Buyer's Guide
Wireshark
February 2025
Learn what your peers think about Wireshark. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.

What do I think about the scalability of the solution?

I probably won't be able to give good input on this, but I will give Wireshark eight out of 10 for scalability based on the limited time that I've used it.

Which solution did I use previously and why did I switch?

I also use MikroTik. It's easy because I've been working with it for years, so it's hard for me to compare it with Wireshark, which I only learned to make my YouTube videos and used a couple of times in the past. 

I'd say Wireshark and Nmap are more advanced and in-depth than using MikroTik by itself, but I haven't encountered a problem I couldn't resolve without using Wireshark. The exception is when a client doesn't have MikroTik, and they use a plain router or something like that. Obviously, I would need to pull out the other tools. MikroTik does what I need it to do. 

How was the initial setup?

Wireshark uses a simple "next, next, finish" installer. Any person who can read can install it.

What other advice do I have?

I rate Wireshark eight out of 10. It has much more network functionality than MikroTik, but the downside is a person has to learn it to use it correctly. Maybe make it my New Year's resolution to watch a tutorial on how to use it and start using it more in the new year.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PraveenMoule - PeerSpot reviewer
System Network Administrator at Mungi Engineers Pvt. Ltd.
Real User
Easy to use and feature-rich
Pros and Cons
  • "Wireshark's best features are that it lets us see what traffic is in the network and what data should be encrypted."
  • "Wireshark could be improved with a delay option when getting data automatically."

What is our primary use case?

I mainly use Wireshark for knowledge purposes, debugging, and to view what's going on in the network.

What is most valuable?

Wireshark's best features are that it lets us see what traffic is in the network and what data should be encrypted.

What needs improvement?

Wireshark could be improved with a delay option when getting data automatically. It could also work faster.

For how long have I used the solution?

I've been working with Wireshark for over five years.

What do I think about the stability of the solution?

Wireshark is stable.

What do I think about the scalability of the solution?

Wireshark is easy to scale.

Which solution did I use previously and why did I switch?

Previously, I used Microsoft Network Monitor but switched to Wireshark because it's open-source and richer in features.

How was the initial setup?

The initial setup is pretty simple.

What about the implementation team?

I implemented Wireshark myself.

What's my experience with pricing, setup cost, and licensing?

Wireshark is open-source and free of charge.

What other advice do I have?

Wireshark is a very nice product that's really easy to use from the start. I would rate it nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Wireshark
February 2025
Learn what your peers think about Wireshark. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
Ahmet Kilic - PeerSpot reviewer
Network and Security Unit Manager at Bankalararası Kart Merkezi (BKM)
Real User
Leaderboard
It's an effective way to troubleshoot unknown issues, but it could use a dashboard

What is our primary use case?

Wireshark is a packet analysis tool. We check Wireshark when we don't know what's causing an issue.  The network packets never lie. Three people on my company's network team use Wireshark. 

How has it helped my organization?

It's an efficient solution for determining unexplained issues. It helps us rule out the network as the cause of an issue. When people don't know the reason for a problem, they always believe it's the network. Wireshark enables us to prove ourselves to the other teams. 

What is most valuable?

Wireshark is a simple solution. 

What needs improvement?

Wireshark doesn't have a dashboard. 

For how long have I used the solution?

We have been using Wireshark for around 10 years.

What do I think about the stability of the solution?

Wireshark is stable. 

What do I think about the scalability of the solution?

Wireshark is scalable.

How was the initial setup?

Setting up Wireshark is easy and usually takes about 10 to 15 minutes. 

What's my experience with pricing, setup cost, and licensing?

Wireshark is open source, but you can pay for support. 

What other advice do I have?

I rate Wireshark seven out of 10. If you use the free version, you can't get technical support, but it's cost-effective. When you first use Wireshark, it can seem complex, but it's an effective solution once you get used to it. Packet analysis is complicated, but it's the best way to do the job once you understand the solution.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Sr. Security Engineer at SugarCRM
Real User
Helps me solve network transaction and security issues
Pros and Cons
  • "I can save the traffic and analysis when I want to. Also, it's especially helpful to follow the stream (TCP, UDP, etc.)."
  • "Setup is very easy. It's also possible to change source code and compile if you want to change something in the code, because it's free."
  • "It needs the ability to follow multiple interfaces for specific traffic from different network zones/virtual networks. It would help to understand how any packet is going through the network."
  • "Sometimes I need to use tcpdump when I need to check the packets on CLI."

How has it helped my organization?

It has help me to 

  • solve network and transaction issues
  • understand protocols and application communication
  • check quality
  • solve security issues. 

What is most valuable?

I can save the traffic and analysis when I want to. Also, it's especially helpful to follow the stream (TCP, UDP, etc.).

What needs improvement?

It needs the ability to follow multiple interfaces for specific traffic from different network zones/virtual networks. It would help to understand how any packet is going through the network.

For how long have I used the solution?

More than five years.

What do I think about the stability of the solution?

Sometimes, in the previous version, it lost the scroll when I needed to scroll back and forth.

What do I think about the scalability of the solution?

No issues with scalability.

Which solution did I use previously and why did I switch?

Sometimes I need to use tcpdump when I need to check the packets on CLI.

How was the initial setup?

Very easy. It's also possible to change source code and compile if you want to change something in the code, because it's free.

What's my experience with pricing, setup cost, and licensing?

It's free.

What other advice do I have?

I believe everyone should use this tool if they need to analyze packets.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Network Engineer at a tech services company with 51-200 employees
Real User
Excels at analyzing and decoding packet capture files and powerful tool for troubleshooting network issues
Pros and Cons
  • "The best part about Wireshark, in my opinion, is its ability to analyze packet capture files."
  • "It is difficult to scale this solution."

What is our primary use case?

There are multiple use cases for Wireshark. One of the primary use cases is capturing the customer's network traffic. When an issue occurs on the customer's network, we take packet captures to analyze and decode the streams that were active during the time of the incident. 

Additionally, we use Wireshark to replay packet streams. This helps us troubleshoot issues that may not be readily observable on the live network. With the packet capture in hand, we can analyze the decoded packets and identify the protocols involved and the specific nature of the issue that occurred.

How has it helped my organization?

It has helped us in debugging challenging customer issues

What is most valuable?

The best part about Wireshark, in my opinion, is its ability to analyze packet capture files. It lists out various protocols like TCP, UDP, or SCTP, along with source and destination codes. This feature is truly amazing.

What needs improvement?

One thing that I feel is currently missing in Wireshark is the ability to perform deep analytics on traffic streams after they have been decoded. While it may not be the major use case right now, it would be beneficial to have some sort of leveraging of artificial intelligence or machine learning to automatically detect threats or vulnerabilities based on specific types of network traffic. Predictive analysis of this nature is currently absent in Wireshark.

So in future releases, it would be great to see more robust analytics for traffic streams in the next version of Wireshark.

One improvement I would suggest is having more graphical representations of network topologies in Wireshark. Currently, when we deploy Wireshark to collect streams, we lack visibility into how different entities are connected at that specific time. Having a network topology view of connected devices, showing the source and destination, would be really beneficial. For example, in DNS troubleshooting, visualizing the network path can help recreate certain issues. Unfortunately, this feature is not currently available in Wireshark.

For how long have I used the solution?

I've been working with Wireshark for more than 13 years. I would consider myself a network software development professional with extensive experience.

I've worked with major companies like Cisco Systems and other networking companies.

What do I think about the stability of the solution?

I would rate the stability of Wireshark as nine out of ten. It's quite stable.

What do I think about the scalability of the solution?

In terms of scalability, I would rate the scalability a seven out of ten. It is difficult to scale this solution. 

The use cases I've worked on require deploying Wireshark independently on each node. However, if I want to deploy Wireshark on hundreds of devices and collect information at a single location for better network management, that capability is currently not available. We need Wireshark to run on all the devices and have one device act as a controller to collect and process the information.

Wireshark is popular among both individual users and enterprise organizations, but currently, it is mostly used individually for debugging network traffic.

How are customer service and support?

I usually troubleshoot issues on my own. However, since Wireshark is open source, there is a community support system available.

How would you rate customer service and support?

Positive

What about the implementation team?

Deployment-wise, Wireshark is relatively simple. It's not overly complex, and it works quite well. So, in that respect, it's a good solution.

We are working with a hybrid model. We deploy Wireshark in both cloud platforms and on-premises. Depending on the real devices and entities, we sometimes deploy it onto virtual machines in the cloud and collect and process information using a switch. This flexible deployment approach allows us to cater to different scenarios and adapt accordingly.

Which other solutions did I evaluate?

I can compare Wireshark with tools like Suricata and Zeek. Suricata and Zeek are both implemented considering setting objectives, meaning that they are designed to achieve specific goals. For example, Suricata is designed to decode packet streams, perform analysis, and push configuration changes to devices. This makes it a good choice for an Intrusion Prevention System (IPS), which is a system that can detect and prevent attacks.

Wireshark is the base of Suricata. Suricata both use the same packet filter implementation, known as BPF (Berkley Packet Filter). BPF is a powerful tool that can be used to capture and analyze network traffic.

What other advice do I have?

In general, I'm quite fond of Wireshark, so I would rate it an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
ASM Naushad Alam - PeerSpot reviewer
Network Manager at a financial services firm with 1,001-5,000 employees
Real User
The best packet capturing tool
Pros and Cons
  • "The most valuable feature is the traffic gate, which shows which IPs are getting more bandwidth or traffic."
  • "Wireshark could be improved by adding more monitoring features."

What is our primary use case?

I mainly use Wireshark to look at traffic conditions when something is getting stopped in our network.

What is most valuable?

The most valuable feature is the traffic gate, which shows which IPs are getting more bandwidth or traffic.

What needs improvement?

Wireshark could be improved by adding more monitoring features.

For how long have I used the solution?

I've been working with Wireshark since 2008.

What do I think about the stability of the solution?

Wireshark is stable.

How was the initial setup?

The initial setup was very simple.

What other advice do I have?

Wireshark is the best packet capturing tool, and I would rate it eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Henry A. McKelvey - PeerSpot reviewer
NextGen TV (ATSC 3.0) Systems Engineer at PeerSpot
Real User
Top 20
Filters enable traffic to be segmented so that a value can be looked at individually apart from the other traffic
Pros and Cons
  • "I use the filters very often, to determine what type of traffic I am looking for. The use of filter allows traffic to be segmented so that a value can be looked at individually apart from the other traffic."
  • "The system could be improved upon by adding a better and more powerful data processing engine."

What is our primary use case?

I use it for network investigation, I even have a patent for the simplification of Protocol Analysis. I have used Wireshark many times to troubleshoot network situations and problems. The patent solved the problem of troubleshooting where you needed to know the direction and course a packet takes in the network which helps with the ability to know where problems lie in the network. We developed the system to actually troubleshoot an entire network through the use of network probes, which acted as smaller protocol analyzers.

How has it helped my organization?

It helped in the sense that it allowed the team to troubleshoot networks faster. While I worked at Verizon, our group was able to provide network analysis of our testbed which gave us an advantage over most test groups. This was because we could follow a packet throughout the network to examine the treatment that the packet was receiving in the network. The improvement came when we realized that through the use of this method we could duplicate the results of using a much more expensive version of our program called RMON.

What is most valuable?

I use the filters very often, to determine what type of traffic I am looking for. The use of filter allows traffic to be segmented so that a value can be looked at individually apart from the other traffic. I remember one day when we had to find out what was causing one of the systems to crash. We used our system to look at the network as a whole and we found that the device actually gave us the ability to segment the network finding the problem is a faster way which allowed for a more accurate test of the network.

What needs improvement?

The system could be improved upon by adding a better and more powerful data processing engine. The original was based on the Raspberry Pi. The RPi unit acted as a sensor on the network relaying information back to a centralized computer which was able to correlate and provide analysis as to the packets and their reaction to traffic loads. Much improvement could have been done but we were not that lucky. The more we designed items the more we began to realize that we were getting too far from our central goal of trying to make the network better.

For how long have I used the solution?

I have been using it since it was called Ethereal.

What do I think about the stability of the solution?

I am impressed with the stability. 

What do I think about the scalability of the solution?

Great scalability, but they are beginning to sacrifice ease of use for complexity. That was why we needed to simplify things.

Which solution did I use previously and why did I switch?

No, we did not use another solution like wire-shark, but what we used in the past was the RADco. The RADcon was a protocol analyzer that was an all in one unit that was the standard at the time but did not allow for cooperative testing.

What's my experience with pricing, setup cost, and licensing?

If you can get the same use for less cost do it.

Which other solutions did I evaluate?

No, we did not.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user1065 - PeerSpot reviewer
Senior Manager of Data Center at a integrator with 51-200 employees
Vendor
Wireshark is the most reputed network protocol analyzer globally

Valuable Features:

Pros of Wireshark are 1) Open Source 2) Support on Windows, Linux, MAC, Solaris 3) Presence of both command shell and graphical user interface 4) Port Mirroring 5) Inbuilt support for WinPcap, libPcap 6) Filter creation for better packet capture techniques

Room for Improvement:

Few cons of Wireshark are 1) Running Wireshark through an admin account for multiple exploits, is unsecured 2) Cannot manipulate things on the network 3) Cannot be used for MIDM attacks 4) Lack of intrusion detection module 5) Lack of modules for ARP poisoning and caching

Other Advice:

Wireshark is the world's most powerful network protocol analyzer tool. It can be used for various purposes such as, analysis of protocols like TCP, HTTP, UDP, and complete analysis of networks and troubleshooting. It has the option to use the wireless adapter directly in promiscuous mode for interception of wireless packets. It is much more effective than other tools such as tcpdump and dumpcap with a good user interface and hex detection.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user