This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

How to count packet loss in summary wireshark

asked 13 Jul, 02:45

wiwiasmara's gravatar image

wiwiasmara
612
accept rate: 0%

Hardly.

To count lost packets, you first have to know that they should have been there. So you need to compare captures taken at source and destination, or there must be some packet numbering in the received flows you are interested in. So edit your question with more details, and you'll het a more detailed answer.

(13 Jul, 03:32) sindy

Do you mean, "How does Wireshark determine the number of dropped packets?"

Wireshark is relying on libpcap (or WinPcap) to report this information. Basically, it's the number of packets that were received and would have been placed into the kernel's buffer but which were dropped because the buffer was full, likely due to Wireshark not reading those packets out of the buffer fast enough.

Refer to Guy Harris' explanation here and my answer to this other question over at Stack Overflow, which is also based on Guy's superb explanations. These questions and answers happen to pertain to tcpdump, but Wireshark relies on the same mechanism essentially.

(If you mean something else, then kindly elaborate as sindy indicated.)

permanent link

answered 13 Jul, 14:27

cmaynard's gravatar image

cmaynard ♦♦
9.3k1038142
accept rate: 20%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×46

question asked: 13 Jul, 02:45

question was seen: 264 times

last updated: 13 Jul, 14:27

p​o​w​e​r​e​d by O​S​Q​A