Do we need new top 10 list for Wireshark 2.0?
Well, not completely. Maybe just a refresh...
First off, most of the filters in Wireshark 2.0 are the same as they were in Legacy Wireshark. The oldies but goodies will still be around and have the same familiar syntax. However there are a couple that we could add to the "Top 10" list that this recent release of Wireshark continues to support. The list that follows is not unique to Wireshark 2.0, but hey, the release is a good excuse for an update.
ip.addr == 10.0.0.1 (Classic. Sets a filter for any packet with 10.0.0.1 as the source or dest IP)
ip.addr eq 10.0.0.1 and ip.addr eq 192.168.1.1 (Sets a conversation filter between two IP's)
ip.addr == 10.0.0.0/24 (Subnet filter. Displays any conversation to or from any IP in the 10.0.0.0/24 subnet)
tcp or dns (Sets a filter for all packets containing TCP and those with DNS)
tcp.analysis.flags (Displays any packet with TCP warnings or info, including retransmissions, duplicate acks, window updates and Out-of-Orders. Also, TCP problems are automatically displayed on the sidebar of the summary view of wireshark. Look for dark lines on the scroll bar as you go through a trace. Great info to spot the bad stuff!)