Wireshark & diagnostics · Video guide

Intro to Wireshark Tutorial // Lesson 3 // Capturing Packets with Dumpcap

Chris Greer11:23Published Apr 29, 2021Intermediate

The player loads only when you choose Watch here. Playback uses YouTube’s privacy-enhanced embed; YouTube processes playback data.

Why this is useful

Demonstrates selecting an interface, writing captures to disk and rotating a ring buffer. Helpful when a GUI capture is impractical or an intermittent fault needs a longer observation window.

Applicability

Version-specific

The capture concepts still apply; Windows and macOS path examples are from 2021.

Keep in mind

  • Check the current dumpcap help for options and units. tcpdump is a separate tool, not necessarily part of a Wireshark installation.
  • A ring buffer overwrites old evidence. Preserve the incident files before they rotate out and apply a time limit where appropriate.

Before you watch

Read the linked introduction, then use the video to reinforce the explanation.

Editorial review Sep 7, 2026. Review used the complete available transcript and primary references; audio and screen readability remain unverified.