Filter by Multicast / Broadcast in Wireshark

When tracking down multicast and broadcast sources it is useful to be able to filter everything to leave only the multicast and broadcast traffic.

To do this in the wireshark GUI enter this into your filter and click apply.

(eth.dst[0] & 1)

It is also worth noting that at the bottom of the screen it displays the total number of packets captured and the number displayed.  This is a nice quick way of seeing just what percentage of your packets are multi/broadcast to this server or span port vs the rest of your traffic.