I have just installed the latest Wireshark on my Macbook Pro. I want to analyze some pcaps that were sent to me. I can open the pcap files just fine, and all looks normal on the screen. However, when I go to filter on 'TCP' and apply the filter, nothing happens. Moreover, when I right-click on the row/packet I am interested in, nothing happens. Any thoughts or ideas are appreciated. asked 21 Jan '14, 16:18 slinky |
One Answer:
well, if the first few frames (the ones visible in Wireshark) are all TCP, you won't see any difference if you apply the display filter:
What does that actually mean? Don't you get a pop-menu where you can select "Follow TCP Stream" (and other options)? If so, here are some questions
Regards answered 24 Jan '14, 07:53 Kurt Knochner ♦ edited 24 Jan '14, 07:54 |