Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 3738] Timestamps wrong for .CAP files from Sniffer / Infin

Date: Tue, 4 Aug 2009 10:50:53 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3738





--- Comment #4 from Bill Meier <wmeier@xxxxxxxxxxx>  2009-08-04 10:50:52 PDT ---
(In reply to comment #3)
> Created an attachment (id=3347)
 --> (https://bugs.wireshark.org/bugzilla/attachment.cgi?id=3347) [details]
> CAP and ENC versions of trace, with DOC explanation
> 
> CAP version has problem 
> ENC version is displayed correctly.
> 
> DOC has screenshots and some explanation.
> 

OK: I know the right magic ("ticks-per-second" and other) to use so that
Wireshark will show the correct timestamps for this capture file.

However: the tricky part is how to determine that this particular magic should
be applied for this capture file.

The normal "differentiating" tests we use on sniffer files to determine the
correct "magic" don't seem to be sufficient in this case.

That is: I have sniffer captures which are the same as this (in terms of the
tests) but which need a different "ticks-per-sec & etc than this capture
requires.

I'm in the process of doing further analysis.


-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.