This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Is there a way that when you run wireshark to ONLY capture lost segments. Or how do I set it to ONLY capture TCP when running the capture?

asked 13 Feb '13, 10:58

Dejavu's gravatar image

Dejavu
11112
accept rate: 0%


Is there a way that when you run wireshark to ONLY capture lost segments.

well, as the segment is lost there is no way to capture it with wireshark ;-)) Why do you want to do that?

Maybe a display filter that detects 'lost segments' is what you need: tcp.analysis.lost_segment

Or how do I set it to ONLY capture TCP

you can use the following capture filter: tcp

Regards
Kurt

permanent link

answered 13 Feb '13, 11:17

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

edited 13 Feb '13, 13:35

Is there a way for it to capture only lost segments?

(13 Feb '13, 11:24) Dejavu

as I said. There is no way to capture something that is lost, as lost means: it is not there ;-)

What are you trying to do?

(13 Feb '13, 13:04) Kurt Knochner ♦
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×36
×26

question asked: 13 Feb '13, 10:58

question was seen: 5,267 times

last updated: 13 Feb '13, 13:36

p​o​w​e​r​e​d by O​S​Q​A