This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi,

I'm trying to perform TCP analysis, or at least learn how to do it, and I would really appreciate some information about the following filter fields.

tcp.analysis.ack_lost_segment tcp.analysis.lost_segment tcp.analysis.duplicate_ack tcp.analysis.retransmission

I'm not really sure about the first two, since I've read in some places that they might be due to drops in Wireshark while capturing, and might not be a real issue of the TCP stream. This is somewhat confusing :(

Thank you in advance!

asked 18 Jun '12, 04:36

fashasha's gravatar image

fashasha
6113
accept rate: 0%


permanent link

answered 18 Jun '12, 06:00

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

Great, it's exactly the page I was looking for! Much appreciated, Kurt.

(18 Jun '12, 07:16) fashasha
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×752
×139
×100
×36

question asked: 18 Jun '12, 04:36

question was seen: 21,438 times

last updated: 18 Jun '12, 07:16

p​o​w​e​r​e​d by O​S​Q​A