Screen Shot 2014-09-01 at 10.58.47 AM

A Minimized Dissector Configuration Profile for Wireshark

If you deal with enormous capture files, speeding up your work process is crucial.

Watch this video for a demonstration and example of how you can solve this issue:

What I have below is a minimized dissector profile you can use.

This is a minimized dissector profile that will reduce Wireshark crashes, speed your carving/parsing jobs, and generally speed up Wireshark activities such as Statistics.

Profiles are one of the most important Wireshark capabilities.  Setting up and using different profiles for different environments, protocols, and tasks is a crucial skill that we teach in our Wireshark courses.  Let’s say you went to the Wireshark site and tried to find some!  Suprisingly, here is what you would get:

Screen Shot 2014-09-01 at 10.58.47 AM

Whaaaaat?????

No worries.  We have an answer below:

Let’s look at what you get with this profile.

What did we do?  We simply went to Analyze> Enabled Protocols, disabled all the protcols and then turned on a minimized set.

Try this profile, and then add or delete protocols as you need to for your purposes.

Again, all of this is a great starting point.  What do you think we are missing?  What would you add?

Let us know here!

To download this ZIP file click here.  Make sure you unzip it into your personal folders, profiles subdirectory:

Screen Shot 2014-08-31 at 10.29.53 PM

We hope this helps you with Wireshark!

Got a better one?  Or have a profile you would like to send to us?  Send it to andyw@cellstream.com – thanks in advance – we share profiles here.

Another way to find profiles, click on “Profile” in the tag cloud.

Leave a Comment

Contact Us Here


Please verify.
Validation complete :)
Validation failed :(
 
Your contact request has been received. We usually respond within an hour, but please be patient. We will get back to you very soon.