This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Trying to find lost packets (segments)

0

Is there a way that when you run wireshark to ONLY capture lost segments. Or how do I set it to ONLY capture TCP when running the capture?

asked 13 Feb '13, 10:58

Dejavu's gravatar image

Dejavu
11112
accept rate: 0%


One Answer:

0

Is there a way that when you run wireshark to ONLY capture lost segments.

well, as the segment is lost there is no way to capture it with wireshark ;-)) Why do you want to do that?

Maybe a display filter that detects 'lost segments' is what you need: tcp.analysis.lost_segment

Or how do I set it to ONLY capture TCP

you can use the following capture filter: tcp

Regards
Kurt

answered 13 Feb '13, 11:17

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

edited 13 Feb '13, 13:35

Is there a way for it to capture only lost segments?

(13 Feb '13, 11:24) Dejavu

as I said. There is no way to capture something that is lost, as lost means: it is not there ;-)

What are you trying to do?

(13 Feb '13, 13:04) Kurt Knochner ♦