Group Network Traffic by App and Domain
The sidebar turns a long packet list into groups you can understand. Instead of reading every row, start with the app, domain, IP address, or imported file that matters to your investigation.
TCP Viewer can use local process information, TLS server names, and observed DNS answers to make these groups. DNS names learned from both UDP and TCP responses can appear in the packet table and sidebar.
Select an app, domain, or IP address to focus the packet table.
1. Benefits
- ✅ See which Mac apps created network traffic.
- ✅ Find every packet linked to one domain or IP address.
- ✅ Expand an app to see the domains and addresses it contacted.
- ✅ Keep live traffic and imported files organized in one sidebar.
- ✅ Pin important apps or domains for faster access with TCP Viewer PRO.
- ✅ Export only the traffic inside a selected group.
2. Use the sidebar
- Start a live capture or open a capture file.
- Expand Apps to browse client applications.
- Expand an app to see its domains and IP addresses.
- Expand Domains to browse destinations across all apps.
- Select any row. The packet table updates to show only packets in that scope.
- Select All Packets to return to the full list.
Use the sidebar search field when the list is long. It keeps parent groups visible so you can still understand where each matching row came from.
3. Work with a sidebar item
Right-click a supported app, domain, or IP row to open actions such as:
- Pin an app or domain for quick access.
- Copy App Name, Copy Domain Name, or Copy IP Address.
- Export as pcap or Export as pcapng for only that group.
- Show in Finder for an app-backed row.
- Delete packets in that scope when the action is available.
Pinning is a PRO feature. Pinned sources appear near the top of the sidebar and can include nested domain and IP rows.
4. Why a domain may be missing
Packets always have network addresses, but a domain name is not guaranteed. TCP Viewer needs evidence such as a DNS answer or a TLS server name. A capture may start after DNS resolution, use an encrypted naming method, connect directly to an IP address, or omit the needed packets.
In those cases, use the IP group or add filters for source and destination addresses.