Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] aggregating packages in one messages

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Andrej van der Zee <andrejvanderzee@xxxxxxxxx>
Date: Fri, 4 Sep 2009 14:21:55 +0900

Hi,

> Hi Andrej,
>
> Yep:)
>
> To see the different streams:
> $ tshark -r test.pcap -q -z conv,tcp

Thank you so much again! This is great.

What does "conversation" actually mean? Is this all the data that is
transmitted back and forth for the duration of the connection? I mean,
what event makes the conversation actually start and when does it end,
provided that the capture file contains the whole conversation?

Thank you,
Andrej

  • Follow-Ups:
    • Re: [Wireshark-users] aggregating packages in one messages
      • From: j . snelders
  • References:
    • Re: [Wireshark-users] aggregating packages in one messages
      • From: Andrej van der Zee
    • Re: [Wireshark-users] aggregating packages in one messages
      • From: j . snelders
  • Prev by Date: Re: [Wireshark-users] FTP analysis
  • Next by Date: Re: [Wireshark-users] tcp segments
  • Previous by thread: Re: [Wireshark-users] aggregating packages in one messages
  • Next by thread: Re: [Wireshark-users] aggregating packages in one messages
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation