Wireshark keyboard shortcuts

Wireshark's current User's Guide documents keyboard navigation, packet search, marking, references, capture controls, and display actions for its desktop application.

Windows, macOS, Linux · 53 shortcuts

Packet navigation

Move through packet rows, panes, protocol trees, and the packet-selection history.

ActionWindowsmacOSLinux
Move to the next paneTabTabTab
Move to the previous paneShiftTabShiftTabShiftTab
Select the next packetDown ArrowDown ArrowDown Arrow
Select the previous packetUp ArrowUp ArrowUp Arrow
Select the next packetCtrlDown ArrowCtrlDown ArrowCtrlDown Arrow
Select the previous packetCtrlUp ArrowCtrlUp ArrowCtrlUp Arrow
Select the next packet in the conversationCtrl.Ctrl.Ctrl.
Select the previous packet in the conversationCtrl,Ctrl,Ctrl,
Move forward in packet-selection historyAltRight ArrowOptionRight ArrowAltRight Arrow
Move backward in packet-selection historyAltLeft ArrowOptionLeft ArrowAltLeft Arrow
Close the selected protocol treeLeft ArrowLeft ArrowLeft Arrow
Open the selected protocol treeRight ArrowRight ArrowRight Arrow
Open the selected tree and its subtreeShiftRight ArrowShiftRight ArrowShiftRight Arrow
Expand all protocol treesCtrlRight ArrowCtrlRight ArrowCtrlRight Arrow
Collapse all protocol treesCtrlLeft ArrowCtrlLeft ArrowCtrlLeft Arrow
Move to the parent protocol treeBackspaceBackspaceBackspace
Toggle the selected tree itemEnterEnterEnter

Marks, comments, and references

Mark packets, add time references or comments, and move between those saved points.

ActionWindowsmacOSLinux
Mark or unmark the selected packetCtrlMCtrlMCtrlM
Mark all packetsCtrlShiftMCtrlShiftMCtrlShiftM
Unmark all packetsCtrlAltMCtrlAltMCtrlAltM
Select the next marked packetCtrlShiftNCtrlShiftNCtrlShiftN
Select the previous marked packetCtrlShiftBCtrlShiftBCtrlShiftB
Ignore the selected packetCtrlDCtrlDCtrlD
Ignore all packets of the selected typeCtrlShiftDCtrlShiftDCtrlShiftD
Unignore packetsCtrlAltDCtrlAltDCtrlAltD
Set or unset a time referenceCtrlTCtrlTCtrlT
Unset all time referencesCtrlAltTCtrlAltTCtrlAltT
Select the next time referenceCtrlAltNCtrlAltNCtrlAltN
Select the previous time referenceCtrlAltBCtrlAltBCtrlAltB
Shift packet timesCtrlShiftTCtrlShiftTCtrlShiftT
Add a packet commentCtrlAltCCtrlAltCCtrlAltC

Capture and display

Start capture, open capture options, and control display settings from the keyboard.

ActionWindowsmacOSLinux
Open capture optionsCtrlKCtrlKCtrlK
Start or stop a captureCtrlECtrlECtrlE
Refresh capture interfacesF5F5F5
Apply the selected field as a columnShiftCtrlIShiftCtrlIShiftCtrlI
Open enabled protocolsShiftCtrlEShiftCtrlEShiftCtrlE
Open configuration profilesCtrlShiftACtrlShiftACtrlShiftA
Open preferencesCtrlShiftPCtrlShiftPCtrlShiftP
Open the User's GuideF1F1F1
Quit WiresharkCtrlQCtrlQCtrlQ

Make a printable Wireshark sheet