Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] [WARNING - NOT VIRUS SCANNED] Negative delta with UDP / SI

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Thu, 20 Jun 2013 14:32:05 -0700
On Jun 20, 2013, at 2:14 PM, Pascal Quantin <pascal.quantin@xxxxxxxxx> wrote:

> I have nothing more to add to Guy's really good explanation. But if you are using Wireshark 1.10.0, be aware that it comes bundled with a small utility (found in the installation folder) allowing you to reorder a capture file according to the packets timestamp. Simply do:

Having an option to do that within Wireshark might be useful as well.

(Having a way for libpcap/WinPcap to fix that problem might also be useful; that might requiring delaying the delivery of packets to libpcap's callers until you're pretty sure some packet with a time stamp before that packet won't arrive.)