ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-dev: Re: [Wireshark-dev] Wireshark (Tshark issue ) help required.

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Mon, 1 Sep 2014 22:15:55 -0700
On Sep 1, 2014, at 6:16 PM, Ravi Inder Singh <raviinder@xxxxxxxxx> wrote:

> When i gave following command on ubuntu
> 
> tshark -2 -F pcap -r tcpdump.pcap -R "tcp and ip" -w  write.pcap
> 
> 1) used -F pcap option i want e.pcap in old pcap format.
> 
> problem/issue :- When i open write.pcap it has loosed his old time/date
> 
>  i.e. tcpdump.pcap  in its Time column is having 26 July 2014  with some time 10.12.34 , but in write.pcap it comes to 1970-01-01 with time 00.00.00  in Time column. 

That didn't happen when I tried this with the top-of-trunk version of TShark.

What version of tshark are you using?  (What does "tshark -v" print?)