ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Ethereal-users: Re: [Ethereal-users] Loading and analyzing multiple capture files

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Hansang Bae <hbae@xxxxxxxxxx>
Date: Thu, 17 Mar 2005 23:38:36 -0500
At 03:12 PM 3/17/2005, mail.ag wrote:
>Greetings:
>[snip]
>The ability to load multiple capture files of the same traffic for analysis would be invaluable for packet loss isolation, but would also be useful for many other types of analysis (as mentioned in one of the above threads, firewall troubleshooting.  If you want to get fancy, you could even consider propagation delay and jitter analysis, though the timing requirements may be a bit onerous (ntp doesn't have the resolution to do this, and commodity NICs may not timestamp correctly).
>
>So, to summarize, I've found tcptrace to be of some use in analyzing multiple copies of the same traffic (for both tcp & udp), but would appreciate any insight others may have in how to handle these problems.


You may find http://clearsightnet.com/products-analyzer.jsp handy.

I wish Ethereal supported TCP bounce diagrams like Packetyzer.  I find that Packetyzer is a bit too buggy for use though.


hsb