Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

Different results in Wireshark and Tshark for the same PCAP file

Hello. I am running Wireshark and Tshark (both of version 2.6.10) on Ubuntu (18.04.4). I loaded the same PCAP file on both of them, and applied the same display filter on both. However, the number of displayed packets is different. What could be the reason?

Thank you.