Solved

wireshark conversation statistics

Posted on 2015-02-07
6
188 Views
Last Modified: 2015-02-07
I got the conversation statistics (see pic). There are 202 IP conversations, 416 tcp conversations, and 1043 udp conversations. I thought that tcp and udp are under IP. That is what showing under Protocol Hierarchy statistics. But looking at the conversations, the sum of conversations of tcp and udp are greater than IP conversations. Am I missing something? Thanks

pic
0
Comment
Question by:leblanc
  • 3
  • 3
6 Comments
 
LVL 2

Accepted Solution

by:
UnHeardOf earned 500 total points
ID: 40595892
if you look at the TCP/UDP tabs you will notice that you may have multiple connections ( conversations ) to the same host.
0
 
LVL 1

Author Comment

by:leblanc
ID: 40595899
Ahhh.. That makes sense.

My duration is 160.034 for the conversation. How do I find out the unit set for the duration. I was thinking ms but I just want to confirm it. Thx
0
 
LVL 2

Assisted Solution

by:UnHeardOf
UnHeardOf earned 500 total points
ID: 40595968
The help documenation regarding the fields for the Conversations is based on seconds. I know you can change the time format on the actual capture itself by going to view > Time Display Format.

Conversation Help Contents

8.4.2. The "Conversations" window
The conversations window is similar to the endpoint Window; see Section 8.5.2, “The "Endpoints" window” for a description of their common features. Along with addresses, packet counters, and byte counters the conversation window adds four columns: the time in seconds between the start of the capture and the start of the conversation ("Rel Start"), the duration of the conversation in seconds, and the average bits (not bytes) per second in each direction.
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 1

Author Comment

by:leblanc
ID: 40596009
Yes. I see it now. That is interesting because my total capture time is 12 minutes and I just saw some duration that is around 660.00. I don't think it is in seconds because it would last longer than my capture time. I don't think I changed the duration in the past because I don't know how. So this must be ms somehow.
0
 
LVL 2

Expert Comment

by:UnHeardOf
ID: 40596017
12 minutes is 720 seconds. So that could be accurate and in seconds.
0
 
LVL 1

Author Comment

by:leblanc
ID: 40596023
Yes you are correct. I just realized that I made a mistake in my calculation. Thx
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Short answer to this question: there is no effective WiFi manager in iOS devices as seen in Windows WiFi or Macbook OSx WiFi management, but this article will try and provide some amicable solutions to better suite your needs.
The article will include the best Data Recovery Tools along with their Features, Capabilities, and their Download Links. Hope you’ll enjoy it and will choose the one as required by you.
This video demonstrates basic masking and how to edit the mask to reveal the desired image.
XMind Plus helps organize all details/aspects of any project from large to small in an orderly and concise manner. If you are working on a complex project, use this micro tutorial to show you how to make a basic flow chart. The software is free when…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now