官术网_书友最值得收藏!

Using time values and summaries

Time format configuration is about how the time column (second from the left on default configuration) will be presented. In some scenarios, there is a significant importance given to this; for example, in TCP connections that you want to see time intervals between packets, when you capture data from several sources and you want to see the exact time of every packet, and so on.

Getting ready

To configure the time format, go to the View menu, and under Time Display Format you will get the following window:

How to do it...

You can chose from the following options:

  • Date and Time of Day (the first two options): This will be good to configure when you troubleshoot a network with time-dependent events, for example, when you know about an event that happens at specific times, and you want to look at what happens on the network at the same time.
  • Seconds Since Epoch: Time in seconds since January 1, 1970. Epoch is an arbitrary date chosen as a reference time for a system, and January 1, 1970 was chosen for Unix and Unix-like systems.
  • Seconds Since Beginning of Capture: The default configuration.
  • Seconds Since Previous Captured Packet: This is also a common feature that enables you to see time differences between packets. This can be useful when monitoring time-sensitive traffic (when time differences between packets is important), such as TCP connections, live video streaming, VoIP calls, and so on.
  • Seconds Since Previous Displayed Packet: This is a useful feature that can be used when you configure a display filter, and only a selected part of the captured data is presented (for example, a TCP stream). In this case, you will see the time difference between packets that can be important in some applications.
  • UTC Date and Time of Day: Provides us with relative UTC time.

The lower part of the submenu provides the format of the time display. Change it only if a more accurate measurement is required.

You can also use Ctrl + Alt + any numbered digit key on the keyboard for the various options.

How it works...

This is quite simple. Wireshark works on the system clock and presents the time as it is in the system. By default you see the time since the beginning of capture.

主站蜘蛛池模板: 博乐市| 抚顺市| 石嘴山市| 合肥市| 盘锦市| 磐石市| 枞阳县| 漳平市| 新巴尔虎右旗| 英德市| 遂宁市| 即墨市| 太谷县| 三台县| 上饶市| 邢台市| 松滋市| 汤原县| 景泰县| 宁城县| 东城区| 迭部县| 嘉禾县| 铁岭县| 嘉善县| 广汉市| 太保市| 宁陵县| 大理市| 新邵县| 板桥市| 镶黄旗| 靖江市| 宁明县| 新乡市| 平昌县| 镇沅| 迭部县| 砚山县| 双流县| 大埔县|