Comparison · neutral framing
wireshark vs tcpdump
Both read the same capture format. One is an analysis environment; the other is a capture utility that fits on a server.
Attributes
Values describe documented behaviour. Anything workload- or hardware-dependent is written as a practice, not a number.
Interface
Graphical analysis
- wireshark
- Documented
- tcpdump
- Not a feature
CLI/headless operation
- wireshark
- TSharksame engine, separate binary
- tcpdump
- Documented
Filters
Capture-time filtering
- wireshark
- Documented
- tcpdump
- Documented
Both use BPF syntax at capture time.
Post-capture display filters
- wireshark
- Rich expression language
- tcpdump
- BPF expressions only
Analysis
Protocol dissection depth
- wireshark
- Very high
- tcpdump
- Summary level
Stream reassembly view
- wireshark
- Documented
- tcpdump
- Not a feature
Statistics and graphs
- wireshark
- Documented
- tcpdump
- Not a feature
Deploy
Installed by default on most servers
- wireshark
- Not a feature
- tcpdump
- Very common
Capture file interoperability
- wireshark
- pcap/pcapng
- tcpdump
- pcap
Files move freely between the two.
Wireshark
GUI analysis with protocol dissection, statistics, coloring rules, streams and filters over a full capture.
Strengths
- Deepest dissection catalogue of any open tool
- Follow-stream view for application exchanges
- Statistics: conversations, I/O graphs, expert info
- Profiles and saved display filters
Limitations
- GUI-centric
- Capture on a remote headless host is not its environment
Consider Wireshark when
- — Detailed protocol questions
- — Teaching and walkthroughs
- — Large captures needing navigation
tcpdump
libpcap capture with BPF filtering and text output, present on almost every Unix.
Strengths
- Runs anywhere, tiny dependency footprint
- Write bounded capture files for later analysis
- Read filters to re-query saved files
Limitations
- No dissection depth by default
- No interactive filtering while capturing
Consider tcpdump when
- — On the server, in a container, over SSH
- — Evidence capture with a size cap
- — Quick yes/no on reachability
The same job, both ways
Capture on the host, analyse on the workstation
wireshark
Open the file, apply `tcp.analysis.retransmission`, then follow the suspect stream
tcpdump
sudo tcpdump -i eth0 -w /tmp/incident.pcap -C 50 -W 4 'host 192.0.2.10 and port 443'
Copy the capture off the host under the same evidence handling as any other artefact.
Sources
Both columns should be checkable against upstream documentation.