官术网_书友最值得收藏!

Using time values and summaries

Time format configuration is about how the time column (second from the left on default configuration) will be presented. In some scenarios, there is a significant importance given to this; for example, in TCP connections that you want to see time intervals between packets, when you capture data from several sources and you want to see the exact time of every packet, and so on.

Getting ready

To configure the time format, go to the View menu, and under Time Display Format you will get the following window:

How to do it...

You can chose from the following options:

  • Date and Time of Day (the first two options): This will be good to configure when you troubleshoot a network with time-dependent events, for example, when you know about an event that happens at specific times, and you want to look at what happens on the network at the same time.
  • Seconds Since Epoch: Time in seconds since January 1, 1970. Epoch is an arbitrary date chosen as a reference time for a system, and January 1, 1970 was chosen for Unix and Unix-like systems.
  • Seconds Since Beginning of Capture: The default configuration.
  • Seconds Since Previous Captured Packet: This is also a common feature that enables you to see time differences between packets. This can be useful when monitoring time-sensitive traffic (when time differences between packets is important), such as TCP connections, live video streaming, VoIP calls, and so on.
  • Seconds Since Previous Displayed Packet: This is a useful feature that can be used when you configure a display filter, and only a selected part of the captured data is presented (for example, a TCP stream). In this case, you will see the time difference between packets that can be important in some applications.
  • UTC Date and Time of Day: Provides us with relative UTC time.

The lower part of the submenu provides the format of the time display. Change it only if a more accurate measurement is required.

You can also use Ctrl + Alt + any numbered digit key on the keyboard for the various options.

How it works...

This is quite simple. Wireshark works on the system clock and presents the time as it is in the system. By default you see the time since the beginning of capture.

主站蜘蛛池模板: 冕宁县| 万宁市| 原平市| 故城县| 东丰县| 兰溪市| 福贡县| 江川县| 新津县| 德州市| 阿尔山市| 都兰县| 仁化县| 航空| 江西省| 金坛市| 佛山市| 本溪| 简阳市| 大宁县| 齐齐哈尔市| 疏附县| 齐齐哈尔市| 商丘市| 林芝县| 观塘区| 库伦旗| 拜城县| 富裕县| 绩溪县| 镶黄旗| 栾城县| 柞水县| 尖扎县| 台东县| 皮山县| 五华县| 苍梧县| 紫金县| 大丰市| 灵台县|