Wireshark is a free and open-source packet analyzer. It allows the user to examine data from a live network, or from a capture file on disk. Wireshark can be used as a simple network troubleshooting tool, as well as for security analysis and software development.
Installing Wireshark on Debian 10 is easy – in this guide, we’ll show you how to do it. We’ll also explain some of the basics of using Wireshark so that you can get started right away. Follow our step-by-step guide to installing Wireshark on Debian 10!
In order to follow our guide to installing Wireshark on Debian 10, you’ll need:
- A connection to the Internet (to download and install packages)
- An account with sudo privileges to install and remove packages. You can set this up by following the instructions here.
Updating Your Source List
Wireshark depends on a number of open-source libraries. We need to make sure that these are up-to-date before we install the program itself. Debian 10 keeps all its packages updated through regular updates, so first we’ll run an update.
sudo apt update -y
During installation, you’ll be asked to allow non-superusers to capture data from your network interfaces. Select Yes to continue.
Installing Wireshark on Debian 10
Now that we’re up-to-date, we can proceed to download and install Wireshark.
1.Wireshark is distributed as a package .deb file. This means that there’s no need to download anything manually. Instead, we can just install it through apt, like any other program on Debian 10.
sudo apt install wireshark -y
2.During installation, you’ll be asked to allow non-superusers to capture data from your network interfaces. Select Yes to continue.
Once you’ve installed Wireshark, run the sudo apt policy wireshark command to check the version of Wireshark you installed.
sudo apt policy wireshark
Now that we’ve installed Wireshark, let’s take it for a quick test drive.
1.First up, start the program by typing sudo wireshark. This opens Wireshark in its own window.
2.You can also open Wireshark from your desktop environment’s menu system.
Wireshark has a graphical user interface (GUI) for capturing packets, as shown below. You’ll be presented with a list of available network interfaces that Wireshark understands. If you want to monitor the interface where your web browser is receiving its Internet connection (for example, wlan0), select the interface and click the Start button.
However, you can also use it from the terminal by typing tshark, followed by a command to capture some traffic. Tshark is a command line program for monitoring network traffic. Together with TShark, it’s part of the Wireshark suite. Just like its GUI equivalent, it can capture packets and then show a description in a terminal window or save them to a file in binary format.
3.You can install tshark by typing the following command into your terminal window:
sudo apt install tshark -y
4.Run the tshark –help command below to see the different options that tshark offers.
5.Run the tshark -D command below to check that your network interfaces are recognized by tshark.
You will get a list of your network interfaces like the one below. Note that some network interfaces may be in the “disabled” state. Not all network interfaces are active by default. You must find the active interfaces. In this demo, it’s interface ens3 and lo.
6.You can find out which interface is active by typing ifconfig in your terminal.
7.Once you’ve identified your desired capture interface, run the tshark -i <interface> command to start capturing packets. Where <interface> is the name of your desired capture interface.
tshark -i ens3
8.Once you’re done capturing data, press Ctrl-C in your terminal window. This will stop the capture process and close tshark. You’ll see the captured data displayed in your terminal window, as shown below.
In this guide, we’ve shown you how to install Wireshark on Debian 10. We also demonstrated the use of Tshark – a command-line tool that can be used together with Wireshark, just like its GUI equivalent.
At this point, you should have a working version of Wireshark installed on your system. Leave your questions and inputs in the comments section below.
For more information, visit the Wireshark website.
Karim Buzdar holds a degree in telecommunication engineering and holds several sysadmin certifications including CCNA RS, SCP, and ACE. As an IT engineer and technical author, he writes for various websites.