> ## Content Index
> Fetch the complete content index at: https://huizhou92.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Exploring gRPC details with WireShark
- URL: https://huizhou92.com/exploring-grpc-details-with-wireshark/
- Published: 2024-05-29T08:31:16.000Z
- Updated: 2026-09-06T11:40:22.000Z
- Author: huizhou92
- Tags: tech, golang, grpc, #lang-en

In the previous article, we learned how to capture gRPC traffic using [Wireshark](https://www.wireshark.org/?ref=huizhou92.com). In this article, we will delve deeper into some details of gRPC. I am using the official example of gRPC [grpc-go/examples/helloworld](https://github.com/grpc/grpc-go/tree/master/examples/helloworld?ref=huizhou92.com).

> This article is first published in the medium MPP plan. If you are a medium user, please follow me in [medium](https://medium.huizhou92.com/?ref=huizhou92.com). Thank you very much.

### Packet Capturing Details

gRPC combines [HTTP/2](https://http2.github.io/?ref=huizhou92.com) and Protocol Buffers, making packet capturing more convenient when you understand these aspects. For instance, when capturing packets with Wireshark, manually set unrecognized HTTP/2 protocols as HTTP/2 (otherwise, it will be parsed as binary over TCP). Also, note that when viewing HTTP/2, do not expect JSON data display (protobuf uses its own compression algorithm).

### Overview of a gRPC Call

![gRPC Call Overview](https://images.yixiao9206.cn/blog-images/2024/05/cc45bdd16d0efaee691d300c49d7a533.jpg) \[Image - gRPC Call Overview\]

From the above image, you can see that in the helloworld gRPC scenario, multiple HTTP2 requests occur when the client calls the server. This can generally be categorized as: `Magic->Settings->Headers->Data->Settings->Window-update, Ping->Ping->Headers, Data, Headers->Window_update, ping->Ping`.

### Settings

From the gRPC call overview image, you can observe two instances of Settings configurations with identical data. The specific data is as follows:  
![Settings.png](https://images.yixiao9206.cn/blog-images/2024/05/6952f2e6212b51417a482f33d57d221b.jpg)

The screenshot of gRPC request Headers reveals some details:

1. The Header data of HTTP/2 is compressed.
2. Headers include method (POST), scheme (http), path (/helloword.Greeter/SayHello), content-type (application/grpc), and more.

![Headers](https://images.yixiao9206.cn/blog-images/2024/05/f06d4653f691e48a9abfc81aa060c7e9.jpg)

### Data

The Headers section primarily consists of data related to the client's request to the server, while the Data section involves the server sending data to the client.

![Data](https://images.yixiao9206.cn/blog-images/2024/05/25b53378668126da1d164d8c0c4fe87c.jpg)

### Another Settings Configuration

The second Settings configuration is almost identical to the first, except for the ACK flag being set to *True*.  
![Settings-2](https://images.yixiao9206.cn/blog-images/2024/05/0c3e3ebd6c8124ab0f30adb05f133f7c.jpg)

### Window\_update, Ping

In an HTTP/2 request, two stream blocks can be included.

![Window_update-Ping](https://images.yixiao9206.cn/blog-images/2024/05/6e1879e411ec933de17c1b254e371244.jpg)

### Ping (Pong)

When the client sends a ping request to the server, the server responds with a pong. The ping shown above is initiated by the client, while the subsequent ping is initiated by the server.

![Pong](https://images.yixiao9206.cn/blog-images/2024/05/65621ce6d64bc4a3030e3d5a990cc8ae.jpg)

The data here represents what the server sends to the client (including header and body), as shown in the following screenshot.  
![Data-2](https://images.yixiao9206.cn/blog-images/2024/05/b4f6e681e96c627667d1c3912e86bf35.jpg)

### Window\_update, Ping

It's evident that not only can the client initiate a ping to the server, but the server can also ping the client in return.

![Window_update](https://images.yixiao9206.cn/blog-images/2024/05/64c7693a994d4b49e61b817b8666d691.jpg)

### Another Ping (Pong)

After the server initiates a ping operation, the client responds with a pong.

![Pong-2](https://images.yixiao9206.cn/blog-images/2024/05/d743aaf91b9bb8482736f472368ecf94.jpg)

## Conclusion

By capturing a gRPC helloworld scenario, this article traced the potential data flow process of a gRPC call. Combining theoretical knowledge of gRPC with the packet capturing content in this article should provide a better understanding of gRPC (focusing on HTTP/2 technology).

## References

- [grpc / grpc.io](https://grpc.io/?ref=huizhou92.com)
- [HTTP/2](https://http2.github.io/?ref=huizhou92.com): Official documentation for HTTP/2
- [Protocol Buffers](https://developers.google.com/protocol-buffers/?ref=huizhou92.com)
- [HTTP/2 and How it Works](https://cabulous.medium.com/http-2-and-how-it-works-9f645458e4b2?ref=huizhou92.com) @Carson