I have a very big TCP dump between two servers. There are only two IP addresses so each conversation is defined by the TCP ports used. My question is how do I group the the data by conversations such that all the output is still there just grouped by unique conversation asked 08 Nov '13, 13:29 mrw_1955 |
2 Answers:
There is no such grouping feature in Wireshark, at least not in the 'main' GUI. What you can do:
Regards answered 08 Nov '13, 15:36 Kurt Knochner ♦ |
try using Splitcap tool, its excellent, works very fast and has various options to manipulate the capture file answered 10 Nov '13, 22:52 deepacket |