compare 2 captures in wireshark
hi guys can anybody tell me where to compare 2 file captures.
hi guys can anybody tell me where to compare 2 file captures.
You should look into the Syncro plugin by Tribelab.
Essentially you run two instances of Wireshark and when you move around in one instance in Packet Details, the scrollbar/packet marker in the other instance moves with it. This means you can easily correlate the two captures for faults, missing packets etc.
Please note that it requires you to install a DLL that essentially opens sockets on your own machine, which may or may not be allowed if you have strict security rules. E.g. I'm not able to do this on my company laptop which is a real pain.
https://community.tribelab.com/course...
It's very nice.
Compare is a rather generic term. But what you can do is merge the two capture files and then look at it.
Please start posting anonymously - your entry will be published after you log in or create a new account.
Asked: 2017-12-06 23:58:23 +0000
Seen: 1,602 times
Last updated: May 04 '18
I too need this answered. Trying to find the best way to see what traffic is being dropped between two L3 switches.
Large monitor and open both traces side-by-side?