Hi, I'm using tshark to analyze HTTPs traffic and I don't want to capture TCP retransmissions. Is there a capture filter I can use for this? asked 23 Mar '17, 05:04 Sarah |
One Answer:
IMHO it's not possible to have a capture filter to ignore retransmits. It's necessary to have the data to be able to detect a retransmit (analyse sequence numbers). An option to ignore retransmits is using a display filter (e.g. answered 23 Mar '17, 05:17 Uli edited 23 Mar '17, 05:18 |
correct, retransmissions need to be diagnosed first, so you can't filter them away during capture.