Different results in Wireshark and Tshark for the same PCAP file
Hello. I am running Wireshark and Tshark (both of version 2.6.10) on Ubuntu (18.04.4). I loaded the same PCAP file on both of them, and applied the same display filter on both. However, the number of displayed packets is different. What could be the reason?
Thank you.
What happens if you:
-R
and the filter;-Y
and the filter (and without-R
);-2
, and-Y
and the filter (again, without-R
)?Are you using the Default profile in Wireshark when working with the PCAP file?
Tshark uses the Default profile if the -C <config profile=""> option is NOT used. Wireshark uses the last last used profile if the -C <config profile=""> option is NOT used.