官术网_书友最值得收藏!

Using time values and summaries

Time format configuration is about how the time column (second from the left on default configuration) will be presented. In some scenarios, there is a significant importance given to this; for example, in TCP connections that you want to see time intervals between packets, when you capture data from several sources and you want to see the exact time of every packet, and so on.

Getting ready

To configure the time format, go to the View menu, and under Time Display Format you will get the following window:

How to do it...

You can chose from the following options:

  • Date and Time of Day (the first two options): This will be good to configure when you troubleshoot a network with time-dependent events, for example, when you know about an event that happens at specific times, and you want to look at what happens on the network at the same time.
  • Seconds Since Epoch: Time in seconds since January 1, 1970. Epoch is an arbitrary date chosen as a reference time for a system, and January 1, 1970 was chosen for Unix and Unix-like systems.
  • Seconds Since Beginning of Capture: The default configuration.
  • Seconds Since Previous Captured Packet: This is also a common feature that enables you to see time differences between packets. This can be useful when monitoring time-sensitive traffic (when time differences between packets is important), such as TCP connections, live video streaming, VoIP calls, and so on.
  • Seconds Since Previous Displayed Packet: This is a useful feature that can be used when you configure a display filter, and only a selected part of the captured data is presented (for example, a TCP stream). In this case, you will see the time difference between packets that can be important in some applications.
  • UTC Date and Time of Day: Provides us with relative UTC time.

The lower part of the submenu provides the format of the time display. Change it only if a more accurate measurement is required.

You can also use Ctrl + Alt + any numbered digit key on the keyboard for the various options.

How it works...

This is quite simple. Wireshark works on the system clock and presents the time as it is in the system. By default you see the time since the beginning of capture.

主站蜘蛛池模板: 兴仁县| 呼和浩特市| 上犹县| 海兴县| 嘉黎县| 会东县| 禹城市| 湄潭县| 绵阳市| 麦盖提县| 安康市| 马鞍山市| 潜山县| 贞丰县| 山东省| 色达县| 临潭县| 孝感市| 盐城市| 如东县| 文成县| 阳西县| 英德市| 孟州市| 淮北市| 江华| 安阳市| 沁阳市| 称多县| 定边县| 涞水县| 津市市| 柘荣县| 万宁市| 丘北县| 临夏县| 昆山市| 东乌珠穆沁旗| 大丰市| 嫩江县| 禹州市|