Wireshark-users: Re: [Wireshark-users] question about timestamp
: Guy Harris <guy@xxxxxxxxxxxx
: Wed, 14 Apr 2010 11:13:22 -0700
On Apr 14, 2010, at 3:27 AM, patient1985@xxxxxx wrote:
> at the moment, I´m working with wireshark. Now I have a question about the timestamp in the wireshark record. How gets wireshark this timestamp
The file is written by dumpcap if you're capturing with Wireshark; dumpcap gets it from libpcap on UN*X and WinPcap on Windows.
libpcap and WinPcap get it from the operating system. Where the operating system gets it depends on which operating system you're using.