October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
Linux

How to Install and Use Wireshark on Ubuntu Linux

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Install Wireshark from Ubuntu’s APT repositories with sudo apt install wireshark, then configure capture access so the packet-capture helper can run with the privileges it needs while the graphical application stays unprivileged. This guide covers Ubuntu 24.04 LTS and 26.04 LTS, choosing an interface, capturing and filtering packets, saving a file, and fixing common permission problems. Captures can contain sensitive network data; only capture traffic you are authorized to inspect.

What Wireshark does—and what it can see

Wireshark is a graphical network-protocol analyzer. It can capture packets visible to a selected interface, decode protocol fields, display packet bytes, filter packets, and open or save capture files such as .pcapng and .pcap. Its command-line counterpart, TShark, uses the same capture and protocol-dissection ecosystem.

A normal capture is not a view of every packet on a network: it generally shows traffic visible to the selected host and interface. Wi-Fi monitor mode, switch mirroring, USB capture, virtual networks, and encrypted application traffic each have separate requirements or visibility limits. Ubuntu’s Wireshark manual describes the program’s capture and file-format options.

Before installing

  • Use a supported Ubuntu installation and an account with sudo access.
  • APT needs network access to retrieve packages.
  • Ubuntu must recognize the interface you intend to capture on.
  • For live capture, you need permission to inspect traffic on that machine and network.

Ubuntu’s package archive lists Wireshark in Universe, including packages for Ubuntu 24.04 LTS and 26.04 LTS. The exact package version depends on your Ubuntu release and enabled updates; the repository version is not necessarily the newest upstream release. See Ubuntu’s Wireshark package listing and Ubuntu’s documentation portal.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Adaptive Network TAP with Built-in Hub Monitor | Non-Intrusive Ethernet Sniffer & Analyzer | Real-Time Packet Capture Tool | Plug-and-Play, Wireshark & Tcpdump Compatible
  • ☑️1.Professional Network TAP for Monitoring: Network TAP for 10/100Base-T Ethernet links, enabling real-time monitoring and data capture. Equivalent to a port mirror on a switch.
  • ☑️2.Multi-Function Sniffer & Analyzer: Acts as a network sniffer, network analyzer, and packet capture tool—ideal for troubleshooting, security auditing, and performance analysis.
  • ☑️3. Wide Software Compatibility: compatible with Wireshark, Tcpdump, and other packet analysis software, Easily integrates with Windows and Linux and MacOS.
  • ☑️4. Reliable Non-Intrusive Monitoring: No drivers or additional setup are required. Simply connect the device to capture both normal traffic and error packets without affecting data transmission. The passive design ensures zero interference with the network.
  • ☑️5. Compact, rugged, and reliable packet capture tool: The compact, pocket-sized metal enclosure is durable and robust, providing effective electromagnetic interference (EMI) shielding to ensure stable network transmission.

Install Wireshark with APT

  1. Refresh the package index:

    sudo apt update
  2. Install the graphical application and its dependencies:

    sudo apt install wireshark

    Ubuntu’s package may also install or configure shared components such as wireshark-common. The official Wireshark installation guide documents APT installation on Debian and Ubuntu.

  3. Check the installed version and capture helper:

    wireshark --version
    dumpcap --version

To see which version APT would install or has installed, use apt policy wireshark. Do not assume Ubuntu’s candidate matches the latest upstream release.

Choose who can capture packets

During package configuration, Ubuntu may ask, “Should non-superusers be able to capture packets?” This setting matters: installing Wireshark alone does not necessarily let an ordinary account capture live traffic. The Debian packaging choice and its consequences are described in the Wireshark Debian packaging instructions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a personal desktop: allow the intended user

Choose Yes if you want your account to capture directly and you accept that membership in the wireshark group grants packet-capture capability. Add your account to the group:

sudo usermod -aG wireshark "$USER"

Log out of Ubuntu and back in so the new group membership applies. For a temporary new shell, newgrp wireshark can activate the group there. Check the active groups with:

groups

The output should include wireshark.

When to choose No

Choose No on a shared machine where capture access should remain restricted, or if you only need to inspect existing capture files. Under this packaging configuration, capture remains restricted rather than being granted to members of the wireshark group.

Change the choice later or revoke access

To revisit the package prompt, run:

sudo dpkg-reconfigure wireshark-common

If you enable ordinary-user capture, add the intended account to the group as above and start a fresh login session. To remove your account’s group access:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
sudo gpasswd -d "$USER" wireshark

Launch Wireshark without running the GUI as root

Open the application launcher, search for Wireshark, and start it, or run:

Rank #2
wireshark

Do not routinely run sudo wireshark. Wireshark’s privilege-separation design keeps the GUI and most analysis code running as your normal user while the limited dumpcap helper handles privileged capture. Running the entire GUI as root increases the amount of software with elevated privileges and can leave root-owned files in your home directory. See the Wireshark Developer’s Guide and capture-privileges documentation.

Find the interface carrying the traffic

Modern Ubuntu systems commonly use predictable interface names rather than assuming eth0 or wlan0. List system interfaces with:

ip link

List interfaces Wireshark can capture on with:

wireshark -D

In the GUI, use the interface list and its packet counters to spot activity. Common names and uses include:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • wlp...: usually wireless networking.
  • enp...: usually wired Ethernet.
  • lo: loopback traffic between processes on the same host.
  • docker0, br-..., and other virtual or tunnel interfaces: traffic on a bridge, container, VPN, or virtual network.

For ordinary internet traffic, choose the active Wi-Fi or Ethernet interface. If a VPN is in use, relevant traffic may appear on its tunnel interface; traffic inside a VM or container may be visible on a virtual interface instead of the physical adapter. The -D option lists capture interfaces; if the list is empty, check permissions, interface state, and whether your execution environment exposes the interface. See the Ubuntu Wireshark manual.

Start a capture, inspect packets, and save it

  1. Open Wireshark and double-click the interface you want, or select it and press the shark-fin Start button.

  2. Generate a small amount of known traffic, such as opening a website or performing a DNS lookup.

  3. Press the red-square Stop button when you have enough data.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  4. Use File → Save As and keep the default .pcapng format unless a specific older tool requires .pcap.

The packet list shows one row per packet with fields such as time, source, destination, protocol, length, and summary. Select a row to inspect its expandable protocol fields and raw hexadecimal/ASCII bytes in the packet details and bytes panes. Menu labels can vary a little by version, but useful actions include right-clicking a field to Apply as Filter or Prepare a Filter, following a TCP stream, and using Statistics views for protocol hierarchy, endpoints, conversations, or I/O graphs.

Rank #3
MATOLUO Ethernet Network TAP with Built-in Hub Monitor, Non-Intrusive Ethernet Sniffer & Analyzer, Real-Time Packet Capture Tool, Plug-and-Play, Wireshark & Tcpdump Compatible
  • ☑️1.Professional Network TAP for Monitoring: Network TAP for 10/100/1000Base-T Ethernet links, enabling real-time monitoring and data capture. Equivalent to a port mirror on a switch
  • ☑️2.Multi-Function Sniffer & Analyzer: Acts as a network sniffer, network analyzer, and packet capture tool—ideal for troubleshooting, security auditing, and performance analysis.
  • ☑️3. Wide Software Compatibility: compatible with Wireshark, Tcpdump, and other packet analysis software, Easily integrates with Windows and Linux and MacOS.
  • ☑️4. Reliable Non-Intrusive Monitoring: No drivers or additional setup are required. Simply connect the device to capture both normal traffic and error packets without affecting data transmission. The passive design ensures zero interference with the network.
  • ☑️5. Compact, rugged, and reliable packet capture tool: The compact, pocket-sized metal enclosure is durable and robust, providing effective electromagnetic interference (EMI) shielding to ensure stable network transmission.

Use display filters first; use capture filters deliberately

Wireshark has two different filter languages and timings. A display filter is applied to packets already captured: it hides non-matching packets from view but does not remove them from the capture. A capture filter is applied before capture, limiting which packets are collected. For beginners, start with display filters because they are reversible; a too-restrictive capture filter can prevent wanted packets from ever being saved.

Display-filter examples

Enter these in the display-filter bar:

  • dns — show DNS packets.
  • http — show HTTP packets.
  • icmp — show ICMP packets.
  • tcp.port == 443 — show TCP packets using port 443.
  • ip.addr == 192.168.1.10 — show IP packets involving that address.
  • ip.addr == 192.168.1.10 && tcp — show TCP packets involving that address.
  • tcp.flags.syn == 1 && tcp.flags.ack == 0 — show initial TCP SYN packets without the ACK flag.

Capture-filter examples

Set a capture filter before starting the capture. These examples use libpcap/BPF syntax:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • host 192.168.1.10 — capture traffic to or from that host.
  • port 53 — capture traffic on port 53.
  • tcp port 443 — capture TCP traffic on port 443.
  • net 192.168.1.0/24 — capture traffic to or from that network.

Filter names and syntax are not interchangeable: in TShark, -f sets a capture filter and -Y sets a display filter.

Use TShark on Ubuntu Server or from a terminal

If you do not need the GUI, install the command-line analyzer separately:

sudo apt update
sudo apt install tshark

For package installation details, see the TShark installation guide. Once capture permissions are configured, these commands cover common tasks:

# List capture interfaces
tshark -D

# Capture 100 packets and save them
tshark -i <interface> -c 100 -w capture.pcapng

# Read a saved capture
tshark -r capture.pcapng

# Read it while displaying DNS packets only
tshark -r capture.pcapng -Y 'dns'

# Capture port 53 traffic (capture filter)
tshark -i <interface> -f 'port 53' -w dns.pcapng

# Print selected fields from DNS packets
tshark -r capture.pcapng -Y 'dns' -T fields -e frame.time -e ip.src -e ip.dst -e dns.qry.name

Here, -i selects the interface, -c stops after the specified packet count, -w writes a capture file, -r reads one, -f applies a capture filter, and -Y applies a display filter. Consult the TShark manual for additional options. If permissions have not been configured, a temporary sudo tshark invocation can help diagnose whether access is the problem, but it is not the preferred routine setup.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Protect capture files

Packet captures may contain DNS queries, internal addresses and hostnames, device identifiers, login metadata, cookies, and unencrypted application data. Keep captures private and limit access to a file with:

chmod 600 capture.pcapng

Reopen the file in Wireshark with wireshark capture.pcapng or inspect it in TShark with tshark -r capture.pcapng. Before sharing a capture, remove or anonymize sensitive traffic where possible; a binary file is not automatically safe to distribute.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot missing interfaces or permission errors

No interfaces are listed, or capture says permission denied

Check access and interface visibility in this order:

Rank #4
2Pcs Wireless Zigbee CC2531 Sniffer Bare Board Packet Protocol Analyzer Module with External Antenna USB Interface Dongle Capture Packet Module
  • The Zigbee CC2531 Sniffer Wireless Transmission Rate: 250 Kbaud;Power Consumption:<20mA (receiving);<25mA (transmission)
  • Protocol Analyzer Operating Frequency:2.405-2.485GHz
  • Wireless CC2531 Sniffer Module USB Dongle, CC2531EMK Compatible, Zigbee USB Dongle
  • Extend out 8 IO ports, can matching different firmware (Sniffer And BTool) to achieve bluetooth adapter and protocol analyzer function
  • Protocol Analyzer Size:41*16*1.6mm,Panel thickness: 1.6 mm
  1. Confirm that your current session has the capture group:

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
    groups

    If wireshark is absent after adding yourself, log out and back in.

  2. Confirm Ubuntu sees network interfaces:

    ip link

    If the interface is down or absent here, Wireshark cannot make it available; address the system or driver state first.

  3. Check what the capture program can list:

    wireshark -D
  4. Check the helper path and, if needed, its capabilities:

    command -v dumpcap
    getcap "$(command -v dumpcap)"

    If dumpcap is missing, confirm the package installation. If you selected No for ordinary-user capture, revisit the package configuration:

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
    sudo dpkg-reconfigure wireshark-common

    Then enable the intended user if appropriate and start a fresh login session.

Do not change permissions on arbitrary binaries as a first response. Wireshark’s capture documentation describes manual Linux capability setup as an advanced fallback, such as sudo setcap cap_net_raw,cap_net_admin+eip /usr/sbin/dumpcap; some systems place the helper at /usr/bin/dumpcap. Prefer the Ubuntu package configuration and verify the actual path before considering manual changes. See Wireshark’s capture-privileges guidance.

Container, virtual machine, or remote session

A container or restricted environment may not have access to the host interface or the Linux CAP_NET_RAW and CAP_NET_ADMIN capabilities needed for capture. Capture on the host where possible. Adding capabilities to a container changes its security boundary and should be done only with an understanding of the implications. In a VM, select its virtual adapter and remember that the hypervisor determines what traffic it can see.

Wi-Fi monitor mode, USB, and encrypted traffic

A capture on a connected Wi-Fi interface generally shows traffic visible to that host; it does not automatically collect every nearby wireless frame. Monitor mode requires a compatible adapter, driver support, and suitable channel configuration, and may interfere with the normal Wi-Fi connection. Ordinary Linux capture capabilities do not automatically enable non-root USB capture; consult the Debian packaging notes for that limitation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Wireshark can still show metadata and protocol structure for encrypted connections, but it cannot simply reveal modern TLS payloads without appropriate session keys, endpoint cooperation, or other valid decryption material.

When to use a newer upstream build

Ubuntu APT is the appropriate default for most users because it integrates with the system package manager and supplies a version selected for that Ubuntu release. Consider an upstream package or another carefully verified source only when you specifically need a feature or fix unavailable in your release’s candidate. Such sources require additional version and dependency maintenance; do not add an unverified PPA just to chase a version number. Compare apt policy wireshark with wireshark --version to identify the installed Ubuntu package before changing sources.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.