Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] Wireshark file format

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: ram singh <ramsingh.600@xxxxxxxxx>
Date: Fri, 6 Mar 2009 14:02:58 +0530

hi....
thanks for ur suggestion, it helped me a lot....!!

On Fri, Mar 6, 2009 at 12:36 AM, <j.snelders@xxxxxxxxxx> wrote:
Hi Ram Singh,

When you select Follow TCP Stream the Follow TCP Stream dialog box pops up
with all the data from this tcp stream.
You can view and save the data in the following formats:
ASCII, EBCDIC, Hex Dump, C Arrays and Raw.

Wireshark also applies a display filter to select all the packets in this
tcp stream.
You can save those packets to a separate .pcap file:
File -> Save As
Packet Range: select -> Displayed

You will find more information in the User's Guide:
http://www.wireshark.org/docs/wsug_html_chunked/ChAdvFollowTCPSection.html
http://www.wireshark.org/docs/wsug_html_chunked/ChIOOpenSection.html
http://www.wireshark.org/docs/wsug_html_chunked/ChIOSaveSection.html#ChIOSaveAs

Hope this helps
Joan


On Thu, 5 Mar 2009 16:15:49 +0530 ram singh wrote:
>
>Hi all,
>         i have been using Wireshark for network analysis.But i can't view
>the saved files(saved using Follow TCP Stream) in Wireshark window.The error
>message reads as below:
>"flow5.pcap" isn't a capture file in a format Wireshark understands.
>Can anybody help me to save the files in proper format and also to view
that
>file.
>___________________________________________________________________________
>Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
>Archives:    http://www.wireshark.org/lists/wireshark-users
>Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
>             mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe





___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
            mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe

  • References:
    • [Wireshark-users] Wireshark file format
      • From: ram singh
    • Re: [Wireshark-users] Wireshark file format
      • From: j . snelders
  • Prev by Date: Re: [Wireshark-users] A simple question about Wireshark: confusion about OICQ
  • Next by Date: Re: [Wireshark-users] Frame details
  • Previous by thread: Re: [Wireshark-users] Wireshark file format
  • Next by thread: [Wireshark-users] tcpdump command
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation