Wireshark-users: [Wireshark-users] Capturing traffic resulting from running a new program

From: "Richard Sargent" <rsargent@xxxxxxxxx>
Date: Sat, 12 Jan 2008 14:10:54 -0500
Most Windows machines seem to be very busy in terms of the amount of network traffic. Is it possible to set up a filter that basically says "ignore everything that is current showing up"? It would make it so much easier to see what a new program is sending and receiving if you could focus on just its traffic.
 
I realize that such a filter would potentially lose some of the programs traffic when it was indistinguishable from that of another program. DNS look up comes to mind, although even then, the new program is likely looking up different addresses from the already running programs.
 
 
While I suspect the answer is no, as it seems like a relatively tough problem, I appreciate any suggestions or answers.
 
Thank you in advance,
Richard Sargent
rsargent@xxxxxxxxx
http://www.pendragonfarm.com/