Ask Your Question

grahamb's profile - activity

2024-07-23 13:11:00 +0000 received badge  Rapid Responder (source)
2024-07-23 13:11:00 +0000 answered a question Relevant Examples for Display Filter Comparison Operators

Enhancement requests should be posted as an issue (marked as enhancement) at the Wireshark GitLab instance.

2024-07-18 15:04:43 +0000 answered a question I am trying to capture synchrophasor IEEE C37.118

I don't know anything about that protocol but it would appear that your capture doesn't include a "configuration frame"

2024-07-18 15:04:43 +0000 received badge  Rapid Responder (source)
2024-07-18 14:58:04 +0000 edited question I am trying to capture synchrophasor IEEE C37.118

I am trying to capture synchrophasor IEEE C37.118 I have the simulation network with hardware in loop interfacing (SEL P

2024-07-18 14:53:28 +0000 edited question I am trying to capture synchrophasor IEEE C37.118

I am trying to capture synchrophasor IEEE C37.118 I have the simulation network with hardware in loop interfacing (SEL P

2024-07-18 10:22:02 +0000 commented question Spurious Retrasmissions false?

So what does the capture setup \ environment look like?

2024-07-18 08:57:26 +0000 commented question Spurious Retrasmissions false?

Can you describe the server side capture setup? As the communication apparently works it would appear this is an artefa

2024-07-18 07:48:07 +0000 commented question Interfaces with asterisk - what is it?

I'm not exactly sure, but seem to be a pseudo interface created by npcap. Maybe the npcap folks have more info. I know

2024-07-17 16:44:17 +0000 commented question not able to select start

Have you installed a capture library? Please post the output of Wireshark -> Help -> About Wireshark -> Wiresh

2024-07-17 14:45:05 +0000 commented question Display filter showing different results on different versions

Unfortunately screenshots are very little help, the capture file is required.

2024-07-17 08:09:10 +0000 commented question Display filter showing different results on different versions

Changes have been made in the later version to improve dissection. Without access to the capture file it's difficult to

2024-07-17 08:07:28 +0000 edited question Display filter showing different results on different versions

Display filter showing different results on different versions Hello, I am trying to inspect traffic for duplicate TCP

2024-07-16 14:05:36 +0000 commented question Regarding synchrophasor analog value reading in wireshark

Can you provide a link to the protocol definition?

2024-07-16 08:42:33 +0000 commented question Windows wireshark custom plugin loading error

This used to occur if folks mixed up x64 and x86 builds in the same build directory. As we don't build x86 now this sho

2024-07-16 08:33:34 +0000 commented question Can't update Wireshark within application

Just in case there's any confusion here. The Wireshark application should NOT be run with elevated privileges, this unn

2024-07-15 11:43:04 +0000 edited question Slowness of SQL client-server app

LAN network and TCP segment of a reassembled PDU (SQL traffic) hello, I have issue with slowness of client-server app -

2024-07-14 14:21:03 +0000 commented answer Trouble converting string number to number with tonumber() function on

@flok, normally we don't close "answered questions, instead you should click the checkmark icon next to the most useful

2024-07-14 14:18:15 +0000 commented question Can't update Wireshark within application

The installer checks for running applications in the Wireshark suite of executables, have you checked for that? What ve

2024-07-12 10:30:15 +0000 edited answer Repetitive issue: TCP Previous Segment was not captured

I'm also encountering this issue in my Wireshark capture. The pattern with the message [4 bytes missing in capture file]

2024-07-12 10:07:47 +0000 commented answer Can't update Wireshark within application

I've found that if the capture is not saved then the update fails. Opening an old capture still allows an update.

2024-07-11 10:23:25 +0000 commented answer Can't update Wireshark within application

4.2.6 was released last night, for reference the release notes are here

2024-07-11 08:35:14 +0000 commented answer Can't update Wireshark within application

See the release notes for 4.2.2 here. There was a bug in the updater (for 4.2.0 and 4.2.1) that requires a manual downl

2024-07-11 08:34:36 +0000 commented answer Can't update Wireshark within application

See the release notes for 4.2.2 here. There was a bug in the updater (for 4.2.0 and 4.2.1) that requires a manual downl

2024-07-11 08:15:56 +0000 edited question Trouble converting string number to number with tonumber() function on

Trouble converting string number to number with tonumber() function on Hey guys, i hope someone has an idea about my pr

2024-07-10 15:41:12 +0000 commented question Using Wireshark in conjunction with iperf3 for throughput testing

The book was written by Laura as part of her teaching materials, Gerald wrote the foreword.

2024-07-06 15:41:56 +0000 commented question The display of Wireshark is strange on a 4K monitor

Could you add the info from the Wireshark -> Help -> About Wireshark -> Wireshark dialog. Hint use the "Copy .

2024-07-06 15:39:44 +0000 commented answer Decode SNMPv3 fails

Few observations from the capture file. The SNMP software appears to be Agent++, that could help to get an insight. St

2024-07-05 08:43:16 +0000 edited question Decode SNMPv3 fails

Decode SNMPv3 fails Hi I have configured a working SNMPv3 connection. So I know the encryption settings and I have alrea

2024-07-04 10:08:03 +0000 answered a question 802.1Q VLAN id

The field name is vlan.id. Does this help:

2024-07-04 10:08:03 +0000 received badge  Rapid Responder (source)
2024-07-03 16:06:45 +0000 edited question tshark fails to extract RTP data from pcap even if it is available

tshark fails to extract RTP data even if it is available Using the command: tshark.exe -r fplay_SVS.pcapng -Y "udp.port

2024-06-28 16:36:01 +0000 commented question negative values in time

No, actually i am checking the dns query response time between our firewall and the DNS server. There i am seeing this

2024-06-28 16:35:35 +0000 commented question negative values in time

No, actually i am checking the dns query response time between our firewall and the DNS server. There i am seeing this

2024-06-27 08:41:50 +0000 edited question File type is neither a supported pcap nor pcapng format

File type is neither a supported pcap nor pcapng format Hello Experts, I am hoping for some help here regarding the er

2024-06-26 08:06:12 +0000 commented question Conflict between wireshark vc++ redistro and an older redistro

@mberlin, as I have many things on my dev machines that can update the vc redist it's impossible to determine which came

2024-06-25 13:40:19 +0000 commented answer Are LIN protocol data supported in BLF files?

As this was a dissector improvement\change rather than a bugfix it wouldn't normally be backported to the stable release

2024-06-25 08:43:32 +0000 commented question Duration field is missing in the QoS data frames with both AX(MTK7915) and BE200 radios.

Please stop posting the same question with different accounts. Accounts will be blocked if this persists. See these qu

2024-06-25 08:43:06 +0000 commented question Duration field is missing in the QoS data frames with both AX(MTK7915) and BE200 radios.

Please stop posting exactly the same question with different accounts. Accounts will be blocked if this persists. See

2024-06-24 13:32:05 +0000 commented question Unable to see duration fields in 802.11 radio info, with AX radios and BE200 radios,

Looks to be a duplicate of https://ask.wireshark.org/question/34808/not-seeing-duration-field-wlan_radioduration-in-some

2024-06-24 09:29:40 +0000 commented question Root cause of client send RST?

As usual with application issues, Wireshark can tell you what happened but not why. Sometimes the why can be inferred f

2024-06-24 09:28:07 +0000 edited question Root cause of client send RST?

Root cause of client send RST? The client run on a K8s node , wose port is 1864 , and the server port is 5432 ,a Postgr

2024-06-24 09:27:19 +0000 commented question NT Status: STATUS_ACCESS_DENIED (0xc0000022) SMB2

Not really a Wireshark question, more one for an SMB2 discussion.

2024-06-20 10:38:18 +0000 commented question LLDP malformed packet

What port is used for both source and destination? It's likely that the LLDP dissector is inadvertently trying to disse

2024-06-20 08:35:18 +0000 edited question Plugin (lua) shows name but nothing else

Plugin shows name but nothing else Hi there, I have a lua script for separating data, as shown I can see the name of the

2024-06-20 08:34:24 +0000 edited question In 802.11 Radio information, duration field is missing when downlink traffic is running on 802.11 BE radios

In 802.11 Radio information, duration field is missing when downlink traffic is running on 802.11 BE radios I am using "

2024-06-20 08:33:36 +0000 commented question traffic down after dscp change

Can you make this into a question, ideally with a capture file link?

2024-06-20 08:32:52 +0000 commented question Not seeing duration field (wlan_radio.duration) in some frames for ax-traffic. Radio used for sniffing- MTK7915

Unfortunately 3.6 is out of support, see https://wiki.wireshark.org/Development/LifeCycle. Can you upgrade?

2024-06-20 08:30:13 +0000 commented question I can't see the scrollbar thumbnail

Here it is: Version 4.2.5 (v4.2.5-0-g4aa814ac25a1). Compiled (64-bit) using Microsoft Visual Studio 2022 (VC++ 14.37,

2024-06-19 13:50:20 +0000 commented answer Decrypt TLS traffic

I think the OP is doing some sort of homework assignment where the pcap and keys are provided so there's no need to conf