An engineer from our group went to customer site and capture their system using Wireshark. Unfortunately he exported the files each time he capture rather than use the save button on the Wireshark... all these exported files are .txt, and we cannot get them back to wireshark... Can anyone help how we can get these .txt files back to wireshark? o
asked 06 Apr '12, 16:29
Unfortunately, you can't - the information shown there doesn't, for example, include the entire contents of the SSDP packet, so some of the raw bytes that from which that packet's information was generated aren't reflected in the output.
You'll either have to use what information you have there to try to diagnose the customer's issue, or you'll have to send somebody out to the customer's site to get more data (and save it as a pcap or pcap-ng file), or get the customer to capture the data themselves.
(txt2pcap cannot help here - it takes raw packet data, in the form of a hex dump as text, and converts it to raw binary data in a pcap file. There's no raw packet data in the output you have.)