How do I capture traffic from the SPAN port using a laptop running wirehshark?

  • 6
  • Question
  • Updated 6 years ago
  • Answered
I need to confirm whether or not the SPAN port is copying data from the switch and sending it to LANGuardian.
Photo of Ryan


  • 6 Posts
  • 0 Reply Likes

Posted 6 years ago

  • 6
Photo of Aisling Brennan

Aisling Brennan, Official Rep

  • 393 Posts
  • 8 Reply Likes
The Windows-based Wireshark tool is effective and easy to use for capturing PCAP files of network traffic.

To capture PCAP files of network traffic using Wireshark, do the following:

1. Download Wireshark from and install it.
2. Go to the Capture section. A list of the network interface cards (NICs) detected on your system is displayed.
3. To start to capture traffic, click on the NIC that is capturing the traffic of interest. The traffic capture begins.
4. To stop capturing the traffic, select Capture > Stop. You should keep the capture file under 500MB as this is the file size limit for LANGuardian utility.
5. To save the capture file, select File -> Save As and specify a name for
the file.

The LANGuardian Administration and User Guide lists some useful Wireshark filter commands on page 103.