Alex Rivera | Logout

Filter by process/PID in Wireshark

Asked 2009-08-27T08:35:54.183
171

Is there a way to filter or follow a TCP/SSL stream based on a particular process ID using Wireshark?

Edit
Report

2 Answers

17

You could match the port numbers from wireshark up to port numbers from, say, netstat which will tell you the PID of a process listening on that port.

answered 2009-08-27T08:51:43.170
4

On Windows there is an experimental build that does this, as described on the mailing list, Filter by local process name

answered 2012-12-28T12:02:27.730

Your Answer