We just raised a $30M Series A: Read our story

Wireshark OverviewUNIXBusinessApplication

Wireshark is #3 ranked solution in top Network Troubleshooting tools. IT Central Station users give Wireshark an average rating of 10 out of 10. Wireshark is most commonly compared to SolarWinds NPM:Wireshark vs SolarWinds NPM. The top industry researching this solution are professionals from a comms service provider, accounting for 28% of all views.
What is Wireshark?
Wireshark is the world's foremost network protocol analyzer.
Buyer's Guide

Download the Network Troubleshooting Buyer's Guide including reviews and more. Updated: November 2021

Wireshark Customers
Comversion, ADP, Talbots

Pricing Advice

What users are saying about Wireshark pricing:
  • "It is free."
  • "This is an open-source product that can be used free of charge."

Wireshark Reviews

Filter by:
Filter Reviews
Industry
Loading...
Filter Unavailable
Company Size
Loading...
Filter Unavailable
Job Level
Loading...
Filter Unavailable
Rating
Loading...
Filter Unavailable
Considered
Loading...
Filter Unavailable
Order by:
Loading...
  • Date
  • Highest Rating
  • Lowest Rating
  • Review Length
Search:
Showingreviews based on the current filters. Reset all filters
Henry A. McKelvey
Systems\Communications Engineer at NAACP
Real User
Top 5
Filters enable traffic to be segmented so that a value can be looked at individually apart from the other traffic

Pros and Cons

  • "I use the filters very often, to determine what type of traffic I am looking for. The use of filter allows traffic to be segmented so that a value can be looked at individually apart from the other traffic."
  • "The system could be improved upon by adding a better and more powerful data processing engine."

What is our primary use case?

I use it for network investigation, I even have a patent for the simplification of Protocol Analysis. I have used Wireshark many times to troubleshoot network situations and problems. The patent solved the problem of troubleshooting where you needed to know the direction and course a packet takes in the network which helps with the ability to know where problems lie in the network. We developed the system to actually troubleshoot an entire network through the use of network probes, which acted as smaller protocol analyzers.

How has it helped my organization?

It helped in the sense that it allowed the team to troubleshoot networks faster. While I worked at Verizon, our group was able to provide network analysis of our testbed which gave us an advantage over most test groups. This was because we could follow a packet throughout the network to examine the treatment that the packet was receiving in the network. The improvement came when we realized that through the use of this method we could duplicate the results of using a much more expensive version of our program called RMON.

What is most valuable?

I use the filters very often, to determine what type of traffic I am looking for. The use of filter allows traffic to be segmented so that a value can be looked at individually apart from the other traffic. I remember one day when we had to find out what was causing one of the systems to crash. We used our system to look at the network as a whole and we found that the device actually gave us the ability to segment the network finding the problem is a faster way which allowed for a more accurate test of the network.

What needs improvement?

The system could be improved upon by adding a better and more powerful data processing engine. The original was based on the Raspberry Pi. The RPi unit acted as a sensor on the network relaying information back to a centralized computer which was able to correlate and provide analysis as to the packets and their reaction to traffic loads. Much improvement could have been done but we were not that lucky. The more we designed items the more we began to realize that we were getting too far from our central goal of trying to make the network better.

For how long have I used the solution?

I have been using it since it was called Ethereal.

What do I think about the stability of the solution?

I am impressed with the stability. 

What do I think about the scalability of the solution?

Great scalability, but they are beginning to sacrifice ease of use for complexity. That was why we needed to simplify things.

Which solution did I use previously and why did I switch?

No, we did not use another solution like wire-shark, but what we used in the past was the RADco. The RADcon was a protocol analyzer that was an all in one unit that was the standard at the time but did not allow for cooperative testing.

What's my experience with pricing, setup cost, and licensing?

If you can get the same use for less cost do it.

Which other solutions did I evaluate?

No, we did not.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
AC
Founder and CEO at a tech services company with 1-10 employees
Real User
Top 20
Free, stable, good community support, and useful for investigation and network visibility

Pros and Cons

  • "Being able to dissect email data and figure out what is inside email messages was the most valuable feature. Such a feature is pretty helpful for an ongoing forensic investigation or when there is a potential insider threat that you are trying to investigate. It allows you to see the network activity of the users you are investigating. It also gives you more visibility into your network. It was very easy to set up. There is a lot of information out there on Google and YouTube about how to use it. There is also community support. If you have any trouble, it is pretty easy to find an answer online. You will have to do some digging only if you have a very specific use case."
  • "Its user interface was a little less friendly. They can make its user interface a little bit more friendly. It is for technical people, and most of the technical people would be able to figure it out, but it would be good to improve its user interface. They can maybe build artificial intelligence into it. Currently, it takes a lot of manpower to analyze and dissect all the data."

What is our primary use case?

I used it for a couple of school projects last semester. We basically had to emulate how to capture packets in transit in a network. After capturing those packets, we analyzed them. We also had to break down email messages and dig out pictures inside email messages.

It was deployed through a cloud. They had set up a subscription for a class VM.

What is most valuable?

Being able to dissect email data and figure out what is inside email messages was the most valuable feature. Such a feature is pretty helpful for an ongoing forensic investigation or when there is a potential insider threat that you are trying to investigate. It allows you to see the network activity of the users you are investigating. It also gives you more visibility into your network.

It was very easy to set up. There is a lot of information out there on Google and YouTube about how to use it. There is also community support. If you have any trouble, it is pretty easy to find an answer online. You will have to do some digging only if you have a very specific use case.

What needs improvement?

Its user interface was a little less friendly. They can make its user interface a little bit more friendly. It is for technical people, and most of the technical people would be able to figure it out, but it would be good to improve its user interface.

They can maybe build artificial intelligence into it. Currently, it takes a lot of manpower to analyze and dissect all the data.

For how long have I used the solution?

I started using it last November. It has been six months.

What do I think about the stability of the solution?

It was pretty stable. It never crashed.

What do I think about the scalability of the solution?

Scalability could be a challenge because you can analyze so much data with Wireshark, which can be hard if you don't have a very specific case or plan for it. 

If there is no automated solution, scalability could be a little bit difficult. It gives you more visibility into your network, and you can see the packets that are coming in and going out of the network. The only challenge is that if it is a big organization, there would be a lot to process. Having an automated solution on the side would probably help.

How are customer service and technical support?

I didn't have to contact them.

How was the initial setup?

It was pretty straightforward. It took less than 20 minutes.

What about the implementation team?

I deployed it myself. It does not require any maintenance.

What's my experience with pricing, setup cost, and licensing?

It is free.

What other advice do I have?

I would advise others to have a game plan for it because there is a lot of data that goes into it. You can analyze a lot of data. Having a very strategic game plan would be ideal.

I would rate Wireshark a ten out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
Find out what your peers are saying about Wireshark, Colasoft, Viavi Solutions and others in Network Troubleshooting. Updated: November 2021.
552,407 professionals have used our research since 2012.
Brad Wilson
Owner at QOS NETWORKING INC
Real User
Top 20
Easy to use with a good command syntax, support protocol capture, works well for network troubleshooting

Pros and Cons

  • "It has a good syntax to put the commands in and get information out of."
  • "The only thing that I don't like is sometimes there is an update, and something that I was using is either no longer there or it has changed."

What is our primary use case?

I basically use Wireshark for network troubleshooting.

What is most valuable?

For simple protocol and packet capture, it is very easy to use.

It has a good syntax to put the commands in and get information out of.

What needs improvement?

The only thing that I don't like is sometimes there is an update, and something that I was using is either no longer there or it has changed. However, this is common when they upgrade software, so it's normal with any software.

Because this product is open-source, sometimes there are contributors who make changes and they aren't properly vetted throughout the whole community. Access to older functionality should stay as a user preference so that they can still use it the old way if they want to.

For how long have I used the solution?

I have been using Wireshark since it first came out, between 10 and 20 years ago.

What do I think about the stability of the solution?

Stability-wise, it is very good.

What do I think about the scalability of the solution?

The scalability is very good and it's simple to do.

How was the initial setup?

The initial setup is straightforward for a technical person. This is not the type of product that can be easily set up by an end-user who is non-technical.

What's my experience with pricing, setup cost, and licensing?

This is an open-source product that can be used free of charge.

What other advice do I have?

This is a good product for quick and easy troubleshooting.

I would rate this solution a ten out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Product Categories
Network Troubleshooting
Buyer's Guide
Download our free Network Troubleshooting Report and find out what your peers are saying about Wireshark, Colasoft, Viavi Solutions, and more!