Try our new research platform with insights from 80,000+ expert users
Siwon Kang - PeerSpot reviewer
Software Engeener at Mbition
Real User
Adaptive, open-source tool for network-related developers
Pros and Cons
  • "Wireshark's best feature is that it's adaptive, which means it's the go-to tool for network-related developers."
  • "Wireshark's UI isn't easy to handle and doesn't have as nice a view as Omnipeek."

What is our primary use case?

I use Wireshark to analyze packets, especially network packets.

What is most valuable?

Wireshark's best feature is that it's adaptive, which means it's the go-to tool for network-related developers, as when the new protocol comes up, it's rapidly applied to the system, so I can just look into the packet. For example, I'm working in the automotive industry, and Wireshark supports some IP protocols, which not many tools do.

What needs improvement?

Wireshark's UI isn't easy to handle and doesn't have as nice a view as Omnipeek.

For how long have I used the solution?

I've been using Wireshark for over twelve years.

Buyer's Guide
Wireshark
October 2025
Learn what your peers think about Wireshark. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
872,922 professionals have used our research since 2012.

What do I think about the stability of the solution?

Wireshark is stable. When it changed its UI from a legacy one to the acute, there were some crashes, but that was a while ago, and now it's pretty much stable.

What do I think about the scalability of the solution?

Wireshark provides some macro functions and a custom parse protocol for the new protocols, so it's quite scalable.

How are customer service and support?

As it's open-source, Wireshark's customer service isn't as sophisticated as private products. Developers are welcome to contribute their help, but if no one is interested in your particular issue, there's likely no mode to come up with a solution. 

How was the initial setup?

The initial setup was straightforward and only took a couple of minutes to complete.

What's my experience with pricing, setup cost, and licensing?

We use the free, open-source version of Wireshark.

What other advice do I have?

The most important thing for new users of Wireshark is to get used to the filtering functions because all the filters are based on command input, so the ability to organize the right filter is essential. I would rate Wireshark eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Rajendra Thakur - PeerSpot reviewer
Incident manager at Cisco
Real User
User-friendly with an easy setup and a nice interface
Pros and Cons
  • "The options that are required to get the details for the packet drops are good."
  • "You need good network connectivity to download during the setup, otherwise, it might take a while."

What is our primary use case?

It's a tool that we use to capture the network and if there is any lag or if there are packet drops.

It's a very useful tool. We are using it to monitor any network depreciation. For example, suppose there's a call going on between two IP phones and one person says that I cannot hear you. There's definitely something wrong. The RTP is getting dropped, and the packets are getting dropped. We need to capture the live call or if there are any prerecord calls for this particular time period. We go ahead and use this tool to find out whether the packets dropped when a packet is dropped and what caused the audio issue or video issue. We actually use it to understand any network issues.

What is most valuable?

I've been using it for quite some time, and I find that it's very user-friendly. The interface is good. 

The options that are required to get the details for the packet drops are good. All the options are available for whatever is required. I can choose any of them and search easily, and I can also pull the report and publish it to the team or whoever requires it. 

It's easy to set up.

What needs improvement?

I can't suggest anything as of now regarding Wireshark. I have never found any issues or had any difficulty using it. Be it connecting the system to the network directly and capturing the data through Wireshark, or for a specific time, it's been flawless. I have got the results every time I've needed them. 

You need good network connectivity to download during the setup, otherwise, it might take a while.

For how long have I used the solution?

I have been using Wireshark for almost six years. I've used it for a while at this point.

What do I think about the stability of the solution?

The solution is stable. It's reliable. It offers good performance There are no bugs or glitches. It doesn't crash or freeze. 

What do I think about the scalability of the solution?

Almost everybody in our company is using the product. That's likely around 1,000 people. Here, we always work on the network devices, and we need to use this tool to understand if there is any issue with that network or if there is any issue with the calls. Therefore, almost everyone uses it within the network team.

In terms of scalability, if you look at it, there's no limit. There's no restriction on how many users can use it. However, it depends on the organization. If you need any approval to download it usually needs special permission. 

How are customer service and support?

I never had to reach out to technical support regarding Wireshark. Whenever I've had to use it, it worked properly and there was no issue to complain about.

How was the initial setup?

It is easy to set up. We just need to download it and choose the options while setting it up. That's it. After that, it should be done.

The download itself doesn't take a lot of time. It depends on the bandwidth of your network. If you're using a good network connection, then it hardly takes a minute to download.

What's my experience with pricing, setup cost, and licensing?

It is open-source. Anyone can download and use it. 

What other advice do I have?

I use the solution to support my customer's environment. I am not a partner or reseller. 

I'd rate the solution ten out of ten.

Wireshark is more of a packet capture tool. If you are in a network environment, where you are supporting the customer and looking after the issues with network drop, network devices, or IP calls, you must have a Wireshark on your PC. This is a tool that gives you a clear-cut idea about where the issue is, and where the packs are dropping. It's an excellent tool. Everyone should start using it.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Wireshark
October 2025
Learn what your peers think about Wireshark. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
872,922 professionals have used our research since 2012.
DeepakKumar - PeerSpot reviewer
Senior Lead Engineer at a wireless company with 10,001+ employees
Real User
Free to use, simple to implement, and reliable
Pros and Cons
  • "The product is simple to implement."
  • "This product needs to improve the UI."

What is our primary use case?

I work on WiFi and I am a customer engineer. We use Wireshark to analyze the sniffer captures or tcpdumps. That's the purpose of the solution.

What is most valuable?

There are very handy filters available in Wireshark.

It’s free and doesn’t cost us anything to use.

The product is simple to implement.

It is a stable solution.

What needs improvement?

In my previous company, we had Omnipeek, and the UI was better than Wireshark. This product needs to improve the UI.

Generally, you can use Omnipeek to capture packets. You can also use Wireshark to capture packets. However, they need a compatible adapter. If we use Wireshark without a compatible adapter, we really don't go to capture packets using it. We already get captures from the field and from customers, and we just use it for analysis.

I would make maybe adding filters easy. There are some options that we can enable to look into the packet. For example, the default installation of Wireshark doesn't have much information. You can just get to see the packet number, the time's terms, the source address, the destination address, and some detailed information. If I want to see the RSSI, the channel number, the protocol information, or the data rate, I need to go and modify some of the configurations to add columns to display this information. I need to spend some time with it. Therefore, the Wireshark default installation could probably include some more crucial information. That would be a little helpful.

For how long have I used the solution?

It's been a pretty long time since I started using the product. It’s been more than five years.

What do I think about the stability of the solution?

Wireshark in general is good. It is stable. We have used it on Windows. We have used it on Linux. We have used it on MacBook and it works pretty well on every platform.

What do I think about the scalability of the solution?

The solution is scalable in the sense you can add it to however many laptops you need to. It's not like you have 500 people using the same Wireshark or using a common license. It is installed on everyone's PC and whoever wants to use it can. We are using the free version. Therefore, getting more people to put it on their PCs also doesn’t cost the company more.

In our company, about 150 people, or many a few more, are using the solution.

How are customer service and support?

We’ve never had the need to reach out to technical support.

Which solution did I use previously and why did I switch?

I used Omnipeek. The UI was better than Wireshark. However, it is quite expensive.

If somebody pays for Omnipeek that heavy price, they also prefer to get a compatible adapter or a compatible card that works with Omnipeek.

In this company, people just use the solution. However, there wasn’t a discount moment when management suggested it to everyone.

How was the initial setup?

The initial setup was pretty easy. It was straightforward. We didn’t find it to be difficult.

It only takes a few minutes to get everything up and running.

What's my experience with pricing, setup cost, and licensing?

The solution is free to use. We do not have to pay any licensing fees.

What other advice do I have?

I’m a customer and end-user.

The solution is installed on my PC.

Wireshark is a pretty good tool if somebody wants to learn packet analysis or just plain, simple debugging of network issues at an L2 or L3 level. It is quite good for anybody, even a beginner. Anybody can use this tool and the installation is simple. The default installation should work quite well.

I’d rate the solution eight out of ten. If they could make the UI a little better and help us to get some more crucial information easily while providing some options to enable certain parameters based on the protocol, I’d give it a ten out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Sagar More - PeerSpot reviewer
Network Security Engineer at Ares Management Corporation
Real User
Free with excellent community support, enables deep packet inspection and is continually being improved
Pros and Cons
  • "The ability to decrypt traffic and the abundance of filters available are both valuable features."
  • "The solution has a steep learning curve. There are so many filters and features that are frequently being updated, it takes research, experience and familiarity to be able to use them. It could be a lot more user-friendly."

What is our primary use case?

We primarily use Wireshark for troubleshooting critical issues in our network, retrieving packet headers using packet capture, and for creating custom apps. There are six people on our team and we all use Wireshark on our devices. 

How has it helped my organization?

When we are stuck with an issue that requires deep packet inspection, we capture the traffic with Wireshark, which allows us to resolve it.  

What is most valuable?

The ability to decrypt traffic and the abundance of filters available are both valuable features.

What needs improvement?

The solution has a steep learning curve. There are so many filters and features that are frequently being updated, it takes research, experience and familiarity to be able to use them. It could be a lot more user-friendly. 

For how long have I used the solution?

I have been using this solution for six years.

What do I think about the stability of the solution?

I think Wireshark is the most stable product of its kind.

What do I think about the scalability of the solution?

The solution is very scalable, you can capture traffic on any device regardless of your vendor. 

How are customer service and support?

We have never needed to use customer service or technical support. Whenever we have an issue, a Google search provides us everything we need through community support including Wireshark tutorials.  

How was the initial setup?

The setup of the product is very simple. It's freeware, just download the .exe, go through the installation and select the desired interface you want to capture traffic on. It's a simple and very straightforward process. 

What's my experience with pricing, setup cost, and licensing?

Wireshark is free software, so you can download it and use it for free with no licensing fees.  

What other advice do I have?

I would rate this solution a nine out of ten. Wireshark has been getting better and better in the time I've been using it and it is a very helpful tool. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Network Specialist at a tech services company with 501-1,000 employees
Real User
Free solution with a large online community, which makes it simple to troubleshoot problems
Pros and Cons
  • "It's easy to troubleshoot issues because there's a large online community."
  • "DNS could be improved."

What is our primary use case?

This solution is deployed on-premises.

What is most valuable?

Wireshark provides many different functions which are very useful for my job. There are a lot of features, and I still haven't used everything yet. It's easy to troubleshoot issues because there's a large online community.

What needs improvement?

DNS could be improved.

For how long have I used the solution?

I have been using this solution for 10 years.

What do I think about the scalability of the solution?

The scalability is pretty good. If I have a big file, I can always divide it into smaller ones. I haven't had any problems with opening big files.

How are customer service and support?

There's a big community of people on the internet involved in Wireshark. There are a lot of free resources on Wireshark. If I ever need anything, I just search on YouTube, and there are people that are analyzing or troubleshooting a particular issue with DNS or with retransmission, etc.

How was the initial setup?

Setup is very easy. It's simple to install it on your PC.

We have a software team that automatically installs the solution on our PC, and a variety of my colleagues use it for troubleshooting. There are multiple teams involved.

What about the implementation team?

Deployment was done in-house.

What's my experience with pricing, setup cost, and licensing?

Wireshark is free software, so you don't have to pay any licensing fee. Individual people can use it and then donate to Wireshark.

What other advice do I have?

I would rate this solution 10 out of 10. 

Wireshark is very good for network engineers. It's free software, and you can install it very easily, and there are a lot of features. I mainly use Wireshark in Windows. My advice is to do research on the internet, especially on YouTube, if you have any troubleshooting issues.

It's a very popular solution, and if you're able to, I think it would be helpful to donate to the organization so people can continue to develop Wireshark.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
MohamedEladawy - PeerSpot reviewer
Service Security Lead at Salam Technology
Real User
Useful, allows you to deeply understand what's going on at the packet level, and helps you analyze adverse signatures
Pros and Cons
  • "I find Wireshark a very useful tool. Its best feature is that it allows me to deeply understand what's going on at the packet level, as well as any adverse signatures that I can analyze. When I need to create an IPS rule, I need to check the traffic deeply to get more insights about the actual traffic, what's the name of certain flags, etc., and I'm able to do all that through Wireshark. The tool is also user-friendly."
  • "A room for improvement in Wireshark is its ease of use for beginners. It could be better. Another room for improvement in the tool is for it to provide more details about the traffic load. At the moment, Wireshark is adequate for me, so there isn't anything I'd like added to it in its next version."

What is our primary use case?

We use Wireshark to check the network traffic, and if there's any network problem or issue, we can check it through the tool. We also use Wireshark during analysis, to check if there's any network connectivity or attempts from the malware to communicate with the C&C server. We use the tool for further analysis and investigation.

What is most valuable?

I find Wireshark a very useful tool. Its best feature is that it allows me to deeply understand what's going on at the packet level, as well as any adverse signatures that I can analyze. When I need to create an IPS rule, I need to check the traffic deeply to get more insights about the actual traffic, what's the name of certain flags, etc., and I'm able to do all that through Wireshark.

The tool is also user-friendly.

What needs improvement?

A room for improvement in Wireshark is its ease of use for beginners. It could be better. Another room for improvement in the tool is for it to provide more details about the traffic load.

At the moment, Wireshark is adequate for me, so there isn't anything I'd like added to it in its next version.

For how long have I used the solution?

I've been using Wireshark for a long time, so I can't remember the exact number of years I've been using it.

What do I think about the stability of the solution?

Wireshark is a stable tool. I didn't see any issues with its stability.

What do I think about the scalability of the solution?

Wireshark is a scalable tool.

How are customer service and support?

We never raised an issue or ticket with the Wireshark technical support team.

How was the initial setup?

The setup process for Wireshark was very simple.

What's my experience with pricing, setup cost, and licensing?

We're using the free version of Wireshark.

Which other solutions did I evaluate?

We didn't try to use other solutions apart from Wireshark.

What other advice do I have?

Two hundred people use Wireshark within the company.

My rating for Wireshark is a nine out of ten because I like it and I use it so much.

I'm only a user of Wireshark.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PraveenMoule - PeerSpot reviewer
System Network Administrator at Mungi Engineers Pvt. Ltd.
Real User
Easy to use and feature-rich
Pros and Cons
  • "Wireshark's best features are that it lets us see what traffic is in the network and what data should be encrypted."
  • "Wireshark could be improved with a delay option when getting data automatically."

What is our primary use case?

I mainly use Wireshark for knowledge purposes, debugging, and to view what's going on in the network.

What is most valuable?

Wireshark's best features are that it lets us see what traffic is in the network and what data should be encrypted.

What needs improvement?

Wireshark could be improved with a delay option when getting data automatically. It could also work faster.

For how long have I used the solution?

I've been working with Wireshark for over five years.

What do I think about the stability of the solution?

Wireshark is stable.

What do I think about the scalability of the solution?

Wireshark is easy to scale.

Which solution did I use previously and why did I switch?

Previously, I used Microsoft Network Monitor but switched to Wireshark because it's open-source and richer in features.

How was the initial setup?

The initial setup is pretty simple.

What about the implementation team?

I implemented Wireshark myself.

What's my experience with pricing, setup cost, and licensing?

Wireshark is open-source and free of charge.

What other advice do I have?

Wireshark is a very nice product that's really easy to use from the start. I would rate it nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Harish (Kumar) - PeerSpot reviewer
Cyber Security and IT Head at a outsourcing company with 51-200 employees
Real User
Top 5Leaderboard
A free and open-source packet analyzer with a useful filtering and coloring feature
Pros and Cons
  • "I like the filtering feature as we can filter data easily. This feature is also available in tcpdump, but it's a simple piece of software. Wireshark is more advanced and has many features. It allows you to filter a lot of things. The output can be filtered easily. The most important feature is colorization. If I say, "Okay, this particular SMB protocol in red, it will show me red." It's easy to identify that protocol or capture data."
  • "It would be better if they offered a hybrid version like My Cloud Control."

What is our primary use case?

I use Wireshark for DT inspection of several protocols and choose different color patterns to make it easy to see the various protocols. It also involves live analysis because I can see the live analysis on the Internet. The main task of Wireshark is to inspect the throttle and live data, and it's doing them.

What is most valuable?

I like the filtering feature as we can filter data easily. This feature is also available in tcpdump, but it's a simple piece of software. Wireshark is more advanced and has many features. It allows you to filter a lot of things. The output can be filtered easily.

The most important feature is colorization. If I say, "Okay, this particular SMB protocol in red, it will show me red." It's easy to identify that protocol or capture data. 

What needs improvement?

It would be better if they offered a hybrid version like My Cloud Control.

For how long have I used the solution?

I have been working with Wireshark for about five years.

What do I think about the stability of the solution?

Wireshark is a stable solution.

What do I think about the scalability of the solution?

Wireshark is a scalable solution. Almost all protocols are covered by Wireshark. 

How are customer service and support?

I have never contacted technical support. If I have an issue with some functionality or operation, I use Wireshark's community support or Google the information I need.

Which solution did I use previously and why did I switch?

I was working with Nmap and Cisco Analyzer, but then I started working with Wireshark. Before that, I used another packet analyzer called tcpdump, which is similar to Wireshark.

How was the initial setup?

The initial setup is straightforward. I just downloaded the software and installed it. I completed the whole process within two minutes. It's very simple.

What about the implementation team?

I implemented this solution. 

What's my experience with pricing, setup cost, and licensing?

I am using the free version of this solution.

What other advice do I have?

It's a user-friendly solution. I can start by capturing the interface's data because it will show me the number of interferences. Then I have to select and begin the inspection.

On a scale from one to ten, I would give Wireshark an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user