THIS IS A TEST INSTANCE. Feel free to ask and answer questions, but take care to avoid triggering too many notifications.

Revision history  [back]

Edit: per the comment, since this PC is the destination of a mirror port, capturing on boot is a reasonable requirement. However, using Wireshark is probably the wrong tool for this - check out dumpcap (see https://packetlife.net/blog/2011/mar/9/long-term-traffic-capture-wireshark/) for the discussion.

The issue of startup was discussed here some time ago: https://osqa-ask.wireshark.org/questions/26932/capture-packets-on-startup-automatically/

Edit: per Your best bet is to capture external to the comment, since this PC machine so you catch all the traffic when it comes up, with no dependence on the order at which capture is started and the destination of a mirror port, capturing on boot is a reasonable requirement. interface comes up. However, using Wireshark is probably the wrong tool for this - check out dumpcap (see https://packetlife.net/blog/2011/mar/9/long-term-traffic-capture-wireshark/) for the discussion.

The issue of I think netsh will do a startup was discussed here some time ago: https://osqa-ask.wireshark.org/questions/26932/capture-packets-on-startup-automatically/capture, too, but still prefer external for cases like this.