This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi everyone,

I have a doubt regarding the frame time. I was using -e frame.time field in tshark inorder to capture time stamp but i was confused about the frame time, it this the time when packet was generated? or it is the arrival time of the packet? Can we calculate the router timestamp? because for example if a packet was sent by server to router at 6:00 AM but the packet arrived to the router at 6:02 AM, i want to calculate router time(i.e.,6:01 AM time), till now i am assuming frame.time is the packet arrival time, please correct me if i was wrong. If wrong is there any filter in tshark to find the router timestamp?

Thanks in advance :)

asked 24 May '17, 15:33

sreenu19's gravatar image

sreenu19
6223
accept rate: 0%


A quick search turns up a lot of information:

In short: packets are stamped (somewhere near) packet arrival time. If you want 'Router time' as you call it, you'll need capture and time stamping in the router itself.

BTW: A retention time of 2 minutes is ridiculously long. Microseconds is more likely.

permanent link

answered 24 May '17, 21:59

Jaap's gravatar image

Jaap ♦
11.7k16101
accept rate: 14%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×1,620
×832
×75
×62
×41

question asked: 24 May '17, 15:33

question was seen: 2,265 times

last updated: 24 May '17, 21:59

p​o​w​e​r​e​d by O​S​Q​A