Wireshark mailing list archives

Re: Pcap file isn't a capture file in a format TShark understands


From: Guy Harris <guy () alum mit edu>
Date: Sat, 23 Jan 2010 11:55:21 -0800


On Jan 22, 2010, at 10:06 AM, kahou lei wrote:

This file is captured by another machine.

How was the file captured on that machine?  What software was used?

I try to use tshark and wireshark with this file on another machine which is not the captured one and it works.

Are you saying that on one machine, TShark and Wireshark can read the "udp.pcap" file, but, on another machine, TShark 
and Wireshark cannot read the *same* "udp.pcap" file?

If so, what versions of TShark and Wireshark are running on those two machines, and, if you run the command "capinfos 
udp.pcap" on the machine where TShark and Wireshark *can* read the file, what does it print?
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe


Current thread: