Preamble frame capture


Is it possible to configure wireshark to capture also the preamble and the SFD bytes of a ethernet frame? If affirmative, how to do this capture?

Apparantly not.
See the Wireshark Wiki: Ethernet -> Packet format.

Nope - but I wonder... why do you need to capture the preamble/SFD? Interesting question.

You'd probably need specialized hardware to capture the preamble and SFD; I think most Ethernet adapters will not provide that to the host, no matter how politely the adapter's driver would like to ask it. :-) I don't know what hardware is available to capture that.

