This is an old revision of the document!


Wireshark

  • Set the necessary filter - to reduce data captured as per below example


  • Set up a ring buffer as per below - below example uses 10GB of space.


  • Disable auto update to reduce load and its not necessary - as we are capturing to a file. Depending on how quickly capture fills up the files - you might want to stop capture automatically instead of overwriting. e.g. Stop Capture after 200 files


Finesse Capture

admin:file list activelog /platform/cli/*
FINESSEpcap.cap00                       FINESSEpcap.cap01
FINESSEpcap.cap02                       FINESSEpcap.cap03
FINESSEpcap.cap04                       FINESSEpcap.cap05
FINESSEpcap.cap06                       FINESSEpcap.cap07
GOR.cap                                 GOR1.cap
GOR_1.cap                               tony.cap
dir count = 0, file count = 12
admin:file get activelog /platform/cli/FINESSEpcap.cap*
Please wait while the system is gathering files info ...
 Get file: /var/log/active/platform/cli/FINESSEpcap.cap00

 Get file: /var/log/active/platform/cli/FINESSEpcap.cap01

 Get file: /var/log/active/platform/cli/FINESSEpcap.cap02

 Get file: /var/log/active/platform/cli/FINESSEpcap.cap03

 Get file: /var/log/active/platform/cli/FINESSEpcap.cap04

 Get file: /var/log/active/platform/cli/FINESSEpcap.cap05

 Get file: /var/log/active/platform/cli/FINESSEpcap.cap06

 Get file: /var/log/active/platform/cli/FINESSEpcap.cap07
done.
Sub-directories were not traversed.
Number of files affected: 8
Total size in Bytes: 308883571
Total size in Kbytes: 301644.12
Would you like to proceed [y/n]?

Reference: https://jimshaver.net/2015/02/11/decrypting-tls-browser-traffic-with-wireshark-the-easy-way/

  • Set the System Environnment variable SSLKEYLOGFILE, e.g. SSLKEYLOGFILE=C:\X-Support\SSL\SSLKeyLog.log
  • Set Pre-Master Secret Log filename in the Wireshark\Preferences\Protocols\SSL - as per below
  • Use Chrome or Firefox
  • Run your wireshark trace!

Changed!

Set SSLKEYLOGFILE to %USERPROFILE%\sslkeysENV.pms run chrome with argument e.g.: “C:\Program Files (x86)\Google\Chrome\Application\chrome.exe” –ssl-key-log-file=%USERPROFILE%\sslkeysARG.pms Also note - latest wiresharks have this setting in the protocol 'TLS' and not the legacy protocol SSL

Firefox

For Java / Tomcat

  • tech-notes/wireshark.1568464588.txt.gz
  • Last modified: 2019/09/14 13:36
  • by gerardorourke