Wireshark keyboard shortcuts
Wireshark's current User's Guide documents keyboard navigation, packet search, marking, references, capture controls, and display actions for its desktop application.
Windows, macOS, Linux · 53 shortcutsFiles and search
Open, save, print, reload, and search capture files from the main window.
| Action | Windows | macOS | Linux |
|---|---|---|---|
| Open a capture file | CtrlO | CtrlO | CtrlO |
| Close the capture file | CtrlW | CtrlW | CtrlW |
| Save the capture file | CtrlS | CtrlS | CtrlS |
| Save the capture file as another file | CtrlShiftS | CtrlShiftS | CtrlShiftS |
| Export packet dissections | CtrlH | CtrlH | CtrlH |
| Print the capture | CtrlP | CtrlP | CtrlP |
| Reload the capture | CtrlR | CtrlR | CtrlR |
| Reload the capture as a file | ShiftCtrlF | ShiftCtrlF | ShiftCtrlF |
| Find a packet | CtrlF | CtrlF | CtrlF |
| Find the next packet match | CtrlN | CtrlN | CtrlN |
| Find the previous packet match | CtrlB | CtrlB | CtrlB |
| Go to a packet | CtrlG | CtrlG | CtrlG |
| Resize packet-list columns | ShiftCtrlR | ShiftCtrlR | ShiftCtrlR |
Marks, comments, and references
Mark packets, add time references or comments, and move between those saved points.
| Action | Windows | macOS | Linux |
|---|---|---|---|
| Mark or unmark the selected packet | CtrlM | CtrlM | CtrlM |
| Mark all packets | CtrlShiftM | CtrlShiftM | CtrlShiftM |
| Unmark all packets | CtrlAltM | CtrlAltM | CtrlAltM |
| Select the next marked packet | CtrlShiftN | CtrlShiftN | CtrlShiftN |
| Select the previous marked packet | CtrlShiftB | CtrlShiftB | CtrlShiftB |
| Ignore the selected packet | CtrlD | CtrlD | CtrlD |
| Ignore all packets of the selected type | CtrlShiftD | CtrlShiftD | CtrlShiftD |
| Unignore packets | CtrlAltD | CtrlAltD | CtrlAltD |
| Set or unset a time reference | CtrlT | CtrlT | CtrlT |
| Unset all time references | CtrlAltT | CtrlAltT | CtrlAltT |
| Select the next time reference | CtrlAltN | CtrlAltN | CtrlAltN |
| Select the previous time reference | CtrlAltB | CtrlAltB | CtrlAltB |
| Shift packet times | CtrlShiftT | CtrlShiftT | CtrlShiftT |
| Add a packet comment | CtrlAltC | CtrlAltC | CtrlAltC |
Capture and display
Start capture, open capture options, and control display settings from the keyboard.
| Action | Windows | macOS | Linux |
|---|---|---|---|
| Open capture options | CtrlK | CtrlK | CtrlK |
| Start or stop a capture | CtrlE | CtrlE | CtrlE |
| Refresh capture interfaces | F5 | F5 | F5 |
| Apply the selected field as a column | ShiftCtrlI | ShiftCtrlI | ShiftCtrlI |
| Open enabled protocols | ShiftCtrlE | ShiftCtrlE | ShiftCtrlE |
| Open configuration profiles | CtrlShiftA | CtrlShiftA | CtrlShiftA |
| Open preferences | CtrlShiftP | CtrlShiftP | CtrlShiftP |
| Open the User's Guide | F1 | F1 | F1 |
| Quit Wireshark | CtrlQ | CtrlQ | CtrlQ |