Read Directional Byte Totals in a Wireshark Conversation
Before describing a connection as an upload, download or unexpected transfer, prepare an evidence table that identifies both endpoints and their contributions.
Use a saved capture you are authorised to inspect. Write down the two endpoints you intend to compare and the relevant time window. Give them neutral labels A and B in your working notes; an unfamiliar address is not evidence that its traffic is improper.
Read the pair and both directions
Open Statistics, Conversations and select the appropriate protocol tab. Each row represents an endpoint pair with directional statistics. Confirm the endpoints before reading the A-to-B and B-to-A counts.
If A sends 3,000 counted bytes to B and B sends 500 to A, their combined total is 3,500. Retain both contributions rather than assigning the total to one endpoint.
Record Limit to display filter. It can be enabled automatically when opening the dialog after applying a display filter. Keep the filtered population distinct from unfiltered conversation totals.
Preserve the scope of the observation
List endpoint identities, directional counts and filter state. When comparing views, identify each intended population before explaining a changed number; a smaller selection alone does not establish traffic loss.
Keep the role question separate from the arithmetic. A useful next investigation might be whether the observed traffic matches an expected task, but that requires context from the responsible system owner. A packet count does not supply that explanation on its own.
When sharing the result, include enough scope to reproduce the comparison while removing irrelevant private identifiers. The accepted observation should state who sent the counted bytes in this capture and under which selection, without turning a directional total into an unsupported diagnosis.
Sources: Wireshark official guide.