Is there a way that when you run wireshark to ONLY capture lost segments. Or how do I set it to ONLY capture TCP when running the capture? asked 13 Feb '13, 10:58 Dejavu |
One Answer:
well, as the segment is lost there is no way to capture it with wireshark ;-)) Why do you want to do that? Maybe a display filter that detects 'lost segments' is what you need: tcp.analysis.lost_segment
you can use the following capture filter: tcp Regards answered 13 Feb '13, 11:17 Kurt Knochner ♦ edited 13 Feb '13, 13:35 |
Is there a way for it to capture only lost segments?
as I said. There is no way to capture something that is lost, as lost means: it is not there ;-)
What are you trying to do?