Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] Netmon 3.3 capture in Wireshark 1.2.1

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Troy Tate <Troy.Tate@xxxxxxxxxxx>
Date: Wed, 2 Sep 2009 07:50:59 -0400

They should at least show in the details tab in Expert info. I suspect that the capture file is corrupted even though the packets show in the detail window.

From: Guy Harris <guy@xxxxxxxxxxxx>
Subject: Re: [Wireshark-users] Netmon 3.3 capture in Wireshark 1.2.1 -
	only	2 packets get Expert Info results
To: Community support list for Wireshark
	<wireshark-users@xxxxxxxxxxxxx>
Message-ID: <65F599A7-45FF-452A-A6B6-F807A0EAABB8@xxxxxxxxxxxx>
Content-Type: text/plain; charset=us-ascii; format=flowed; delsp=yes


On Sep 1, 2009, at 11:43 AM, Troy Tate wrote:

> I have a packet capture from a Windows machine running Network Monitor 
> 3.3. I am trying to analyze in Wireshark 1.2.1 (running on Vista 
> Ultimate). Only the first two packets (syn, syn/ack) are getting 
> analyzed under Expert Info.

What are you expecting Wireshark to say about the other 64 packets?   
Perhaps it's not finding anything to say about them.

Troy Tate


=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
Notice: This message, including any attachments, may contain
confidential or privileged information and is intended solely
for the person or entity to whom it is addressed. The use,
disclosure, copying, distribution or reliance on the contents
of this message by anyone other than the intended recipient
is strongly prohibited. If you have received this message in
error, please notify the sender by replying to this message
and then delete it from your system. Thank you.
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

  • Follow-Ups:
    • Re: [Wireshark-users] Netmon 3.3 capture in Wireshark 1.2.1
      • From: Guy Harris
  • Prev by Date: Re: [Wireshark-users] How can I obtain the application layer protocol using "tshark -T fields -e ??"
  • Next by Date: Re: [Wireshark-users] How can I obtain the application layer protocol using "tshark -T fields -e ??"
  • Previous by thread: [Wireshark-users] compiling static tshark binaries with wireshark 1.2.1 on solaris x86
  • Next by thread: Re: [Wireshark-users] Netmon 3.3 capture in Wireshark 1.2.1
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation