Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

Packet captures.

If a time in a packet capture is from 1969, it's probably a time stamp with a value of 0 or near 0; time stamps in the "native" file formats used by Wireshark, pcap and pcapng, are time stamps in the form of seconds and fractions of a second since the "UN*X epoch", which is January 1, 1970, 00:00:00 UTC. That time is, in time zones west of the Greenwich meridian, some time on December 31, 1969.

You would have to ask whoever provided the packet capture why it had time stamps like that.