Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] getting absolute time of packet

From: yuva raj <ubuntuv@xxxxxxxxx>
Date: Thu, 27 Dec 2012 17:45:20 +0530
hi,

I am using tethereal.  I captured few packets, in which 10th packet is tcp with timestamp 1.2436.

I set a filter for tcp and saved the filtered packets to another file.  The resultant file the tcp packet as first packet and timestamp as 0.0000

Can someone tell me how to save the filtered packets and keep the timestamp intact.  I want to get the timestamp 1.2436, as it is in my resultant file.

I tried the options in tethereal '-t a' and '-t r', but both resulted the same, i.e. timestamp 0.0000

Thanks in advance.
uv.