Appendix B. Files and Folders

Wireshark 2.1

Appendix B. Files and Folders

B.1. Capture Files

B.1.1. Libpcap File Contents

  • The timestamp with millisecond resolution
  • The packet length as it was “on the wire”
  • The packet length as it’s saved in the file
  • The packet’s raw bytes

B.1.2. Not Saved in the Capture File

  • Current selections (selected packet, …)
  • The number of packets dropped while capturing
  • Packet marks set with “Edit/Mark Packet”
  • Time references set with “Edit/Time Reference”
  • The current display filter