Wireshark is a free and open-source packet analyzer. It allows the user to examine data from a live network, or from a capture file on disk. Wireshark can be used as a simple network troubleshooting tool, as well as for security analysis and software development.

Installing Wireshark on Debian 11 is easy – in this guide, we’ll show you how to do it. We’ll also explain some of the basics of using Wireshark so that you can get started right away. Follow our step-by-step guide to installing Wireshark on Debian 11. The instructions have been tested on Debian 10 too.

Prerequisites

In order to follow our guide to installing Wireshark on Debian 10, you’ll need:

  • A connection to the Internet (to download and install packages)
  • An account with sudo privileges to install and remove packages. You can set this up by following the instructions here.

Updating Your Source List

Wireshark depends on a number of open-source libraries. We need to make sure that these are up-to-date before we install the program itself. Debian 10 keeps all its packages updated through regular updates, so first we’ll run an update.

sudo apt update -y

During installation, you’ll be asked to allow non-superusers to capture data from your network interfaces. Select Yes to continue.

Installing Wireshark on Debian 11

Now that we’re up-to-date, we can proceed to download and install Wireshark.

Wireshark is distributed as a package .deb file. This means that there’s no need to download anything manually. Instead, we can just install it through apt, like any other program on Debian 10.

sudo apt install wireshark -y

During installation, you’ll be asked to allow non-superusers to capture data from your network interfaces. Select Yes to continue.

Install Wireshark

Testing Wireshark

Now that we’ve installed Wireshark, let’s take it for a quick test drive.

First up, start the program by typing sudo wireshark. This opens Wireshark in its own window.

sudo wireshark

You can also open Wireshark from your desktop environment’s menu system.

Wireshark icon

Wireshark has a graphical user interface (GUI) for capturing packets, as shown below. You’ll be presented with a list of available network interfaces that Wireshark understands. If you want to monitor the interface where your web browser is receiving its Internet connection (for example, wlan0), select the interface and click the Start button.

Wireshark network Analyzer

However, you can also use it from the terminal by typing tshark, followed by a command to capture some traffic. Tshark is a command line program for monitoring network traffic. Together with TShark, it’s part of the Wireshark suite. Just like its GUI equivalent, it can capture packets and then show a description in a terminal window or save them to a file in binary format.

You can install tshark by typing the following command into your terminal window:

sudo apt install tshark -y

Install tshark

Run the tshark –help command below to see the different options that tshark offers.

Run tshark

Run the tshark -D command below to check that your network interfaces are recognized by tshark.

tshark -D

tshark -D

You will get a list of your network interfaces like the one below. Note that some network interfaces may be in the “disabled” state. Not all network interfaces are active by default. You will have to find the active interfaces. In this demo, it’s interface ens3 and lo.

You can find out which interface is active by typing ifconfig in your terminal.

ifconfig

Find active interface using ifconfig command

Once you’ve identified your desired capture interface, run the tshark -i <interface> command to start capturing packets. Where <interface> is the name of your desired capture interface.

tshark -i ens3

Once you’re done capturing data, press Ctrl-C in your terminal window. This will stop the capture process and close tshark. You’ll see the captured data displayed in your terminal window below.

Run tshark for the active interface

Conclusion

In this guide, we’ve shown you how to install Wireshark on Debian 10. We also demonstrated the use of Tshark – a command-line tool that can be used together with Wireshark, just like its GUI equivalent.

At this point, you should have a working version of Wireshark installed on your system. Leave your questions and inputs in the comments section below.

For more information, visit the Wireshark website.

How to Install Wireshark Network Analyzer on Debian 11

Karim Buzdar

About the Author: Karim Buzdar holds a degree in telecommunication engineering and holds several sysadmin certifications. As an IT engineer and technical author, he writes for various web sites. You can reach Karim on LinkedIn