This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi there,

Does anyone know of a way to take a packet capture and plot TCP sequence numbers against timestamp option values?

Thanks, Harry

asked 07 Dec '14, 11:56

pottedcactus's gravatar image

pottedcactus
16114
accept rate: 0%


You could try the standard TCP Stream Graph, maybe that's "good enough" for your purpose.

Statistics -> TCP Stream Graph -> Time Sequence Graph

Please be aware, that you will get different graphs, if you choose a frame from C->S versus S->C!

If you really need a graph the the TCP timestamp option, you'll have to create the graph yourself.

tshark -nr input.pcap -Y "display filter" -T fields -e frame.number -e tcp.seq -e tcp.options.timestamp.tsval

Please replace "display filter" with the wireshark display filter you need to extract data from the right connection in the pcap file.

Then take that output and feed it into Excel or another spreadsheet software to create the graph.

Regards
Kurt

permanent link

answered 08 Dec '14, 05:12

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

edited 08 Dec '14, 05:13

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×752
×72
×62
×39
×6

question asked: 07 Dec '14, 11:56

question was seen: 4,499 times

last updated: 08 Dec '14, 05:13

p​o​w​e​r​e​d by O​S​Q​A