Wireshark. Every byte. Every connection. Every IP.
gerbil
Industrious Poster
4,208 posts since May 2005
Reputation Points: 239
Solved Threads: 300
Well, wireshark is a packet capture tool, and that's what it does. If you are trying to learn the gist of captures then one suggestion is to turn off all but one traffic source application. Next is to construct useful display filters so you see only the traffic you are interested in; once you have that set then to reduce the capture file size you can set a capture filter that accords with what you wish to display. eg... you could ignore a running bit torrent download and concentrate on email packets, say. Take note, too, of the colouring rules - they identify the type of packet.
Packets are not very human-friendly, in general.... you are seeing computer chit-chat.
gerbil
Industrious Poster
4,208 posts since May 2005
Reputation Points: 239
Solved Threads: 300