Clearing filters in Wireshark means removing the display rules you've set so you can see all network traffic again

When you've been filtering network packets in Wireshark — whether by IP address, protocol, or port — you may want to see everything that's flowing across your network without restrictions. Clearing filters is straightforward: click the X button next to the filter bar at the top of the window, or press Ctrl+A to select all packets and remove any active filter. The filter bar itself (where you typed rules like ip.addr == 192.168.1.1) will empty, and Wireshark will redraw to show all captured packets.

There's a difference between clearing a filter you're currently using and clearing the filter history so old filters don't clutter your dropdown menu. Both are useful depending on what you're trying to do, and both take just a few clicks.

Key Takeaways

  • Click the X button in the filter bar or press Ctrl+A to remove the active filter and see all packets again.
  • If you want to keep the filter but temporarily see all traffic, click the X; if you want to delete it permanently, clear it from the filter history in Preferences.
  • Wireshark stores your past filters in a dropdown menu so you can reuse them — this history is separate from the active filter.
  • Clearing filters does not delete captured packets; it only changes what Wireshark displays on screen.

The quickest way: remove the active filter with one click

The fastest method is to look at the filter bar — the white text box near the top of Wireshark where your filter rule appears. On the right side of that box, you'll see an X button in a circle. Click it. The filter disappears, the bar clears, and Wireshark redraws the packet list to show every packet in your capture, not just the ones matching your rule.

If you prefer keyboard shortcuts, select all packets with Ctrl+A, then press Delete or use the menu Edit > Clear All Filters. Either way, the result is the same: your filter is gone and you're looking at the full traffic again.

Clearing filters from the history dropdown

Every filter you type into Wireshark gets saved in a dropdown menu. The next time you click in the filter bar, you'll see a list of past filters you can click to reuse. Over time, this list grows and can become cluttered with old rules you no longer need.

To clear individual filters from this history, click in the filter bar and look at the dropdown menu that appears. Find the filter you want to remove, right-click it, and select Remove. To clear the entire filter history at once, go to Edit > Preferences, then navigate to Appearance > Columns (or search "filter" in the Preferences window). Look for the filter history section and click Clear. This removes all saved filters from the dropdown but does not affect any filter you currently have active.

Why you might want to clear filters

You clear filters when you've been troubleshooting a specific problem — say, tracking down why traffic to a particular server is slow — and now you want to see the bigger picture. Removing the filter lets you spot patterns you might have missed while zoomed in on one type of packet.

You also clear filters when you're switching tasks. If you were analyzing DNS traffic and now you need to look at HTTP, removing the DNS filter first means you won't accidentally miss HTTP packets because they're being hidden by the old rule.

The difference between clearing and resetting

Clearing a filter removes it from view but does not change your captured packets. If you clear a filter and then want it back, you can retype it or select it from the dropdown history (if you haven't cleared the history). Resetting Wireshark entirely — which you do through File > Quit and restarting the program — closes your capture and starts fresh.

If you want to keep your capture but just remove the filter temporarily, use the X button. If you want to start a completely new capture with no filters and no history, close Wireshark and reopen it.

Clearing filters without losing your capture

A common worry: if I clear the filter, will I lose the packets I captured? The answer is no. Clearing a filter only changes what Wireshark displays on screen. All the packets you captured remain in memory (or in the save file if you saved the capture). Removing a filter simply shows you packets that were hidden before.

This is why you can filter, clear the filter, apply a different filter, and move between views without losing any data. The packets themselves never change — only what you see changes.

Frequently Asked Questions

Can I undo a filter I just cleared?

Yes. If you cleared a filter by accident, click in the filter bar and look at the dropdown menu — your filter should still be in the history. Click it to reapply it. If you cleared the entire filter history, you'll need to retype the filter rule.

What if the X button doesn't appear in the filter bar?

The X button only shows when you have an active filter. If the filter bar is empty, there's nothing to clear. If you typed a filter but the X doesn't appear, check that you pressed Enter to apply it — typing alone doesn't activate the filter.

Does clearing filters affect saved capture files?

No. Filters are temporary display rules. When you save a capture file, Wireshark saves the packets themselves, not the filters. When you reopen the file, you'll see all packets again unless you apply a new filter.

How do I clear filters without using the mouse?

Press Ctrl+A to select all packets, which removes any active filter. Alternatively, click in the filter bar and press Ctrl+A to select all the text, then press Delete to clear it and press Enter to apply the empty filter.