Capture files compressed with gzip can be decompressed on the fly Read/write many different capture file formats: tcpdump (libpcap), Pcap NG, Catapult DCT2000, Cisco Secure IDS iplog, Microsoft Network Monitor, Network General Sniffer® (compressed and uncompressed), Sniffer® Pro, and NetXray®, Network Instruments Observer, NetScreen snoop, Novell LANalyzer, RADCOM WAN/LAN Analyzer, Shomiti/Finisar Surveyor, Tektronix K12xx, Visual Networks Visual UpTime, WildPackets EtherPeek/TokenPeek/AiroPeek, and many others The most powerful display filters in the industry Captured network data can be browsed via a GUI, or via the TTY-mode TShark utility Multi-platform: Runs on Windows, Linux, OS X, Solaris, FreeBSD, NetBSD, and many others
Deep inspection of hundreds of protocols, with more being added all the time Wireshark has a rich feature set which includes the following: It is the de facto (and often de jure) standard across many industries and educational institutions. It lets you capture and interactively browse the traffic running on a computer network.
Wireshark is the world's foremost network protocol analyzer.