Frank,
Is the capture file in libpcap format? Or did you
make it with another tool that uses a different file format?
If you did not make the capture file with wireshark
(or tshark), could you run capinfos on it? Capinfos is included in the wireshark
distribution, use it like "capinfos <file>".
The reason I'm asking is that maybe wiresharks
import routine for this file format is not getting the timestamps
right.
Cheers,
Sake
----- Original Message -----
Sent: Sunday, January 18, 2009 11:25
PM
Subject: [Wireshark-users] Fw: Re:
Strange Delta Time
--- On Sun, 1/18/09, Frank Pall <fpall77@xxxxxxxxx>
wrote:
From:
Frank Pall <fpall77@xxxxxxxxx> Subject:
Re: [Wireshark-users] Strange Delta Time To: "Sake Blok" <sake@xxxxxxxxxx> Date: Sunday,
January 18, 2009, 5:23 PM
Hello and thanks for your reply, the only filter
i'm using has the simple rule to visualize only UDP traffic,and
i have already added the Delta Time column.I attach the debug
output and the screenshots of the two sniffer programs i have
used.
In the test,i have set the timer interval to 10
milliseconds,being aware that the minimum timer resolution of
windows XP is about 16 miliseconds. PacketMon and the Debug
output show similar results (packets sent every 16
milliseconds);wireshark shows a time difference approximately
equal to 6.6 milliseconds. Probably i am making some silly
mistake,or misunderstanding what i see...
--- On
Sun, 1/18/09, Sake Blok <sake@xxxxxxxxxx>
wrote:
From:
Sake Blok <sake@xxxxxxxxxx> Subject: Re:
[Wireshark-users] Strange Delta Time To: fpall77@xxxxxxxxx,
"Community support list for Wireshark"
<wireshark-users@xxxxxxxxxxxxx> Date: Sunday, January
18, 2009, 10:24 AM
On Sun, Jan 18, 2009 at 06:48:12AM -0800, Frank Pall wrote: > i am using wireshark 1.0.5 to capture traffic from a program i am writing > in VB6. > In this program,i need to generate a packet every 10ms,but,during my > tests,i am noticing that the Delta Time of each generated packet is about > half of the real one (which i print out in the VB debug window). > I also monitored the traffic with another software (AnalogX > PacketMon),which seems to show a delta time more consistent with the one i > can see in my debug session.
> Am i doing something wrong? Is it related to some wireshark setting?
Were you using a display filter to display only the packets that were generated by your program? In that case, you might have chosen the "Delta Time" option for your column. This is the time between the packet and the packet before this packet in the capture file. If you want to see the delta time between displayed packets, you need to use "Delta Time Displayed" instead.
If this is not the case, could you attach a small capture file to your reply in which this problem is visible? Preferably accompanied by the timestamps from your debug window.
Cheers, Sake
| |
___________________________________________________________________________ Sent
via: Wireshark-users mailing list
<wireshark-users@xxxxxxxxxxxxx> Archives:
http://www.wireshark.org/lists/wireshark-users Unsubscribe:
https://wireshark.org/mailman/options/wireshark-users
mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe
|