I need help with analyzing Wireshark captured packets


I need some help with analyzing captured data using Wireshark. What is the difference between large Delta times (“Time” column by selecting View | Time Display Format | Seconds Since Previous Displayed Packet) and  TCP delta time [(“Calculate Conversation Timestamp” setting  (Edit | Preferences | (+) Protocols | TCP)?] And how can I use these filters to troubleshoot a slow network issue?

Thank you.
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Bill BachPresident and Btrieve GuruCommented:
Delta Time is the time since the previous displayed packet.  This in the time difference between ANY two packets, and may or may not have any bearing on a specific conversation.  However, if you select a single conversation (right-click/Conversation Filter/TCP), then you will be looking at ONLY those packets from the current conversation, and the numbers should be identical.

You'll see the difference mainly when two conversations are going on at the same time:
0.001  A->B
0.002  C->D
0.003  B->A
0.004  D->C

Notice that the delta time between packets 1 and 2 is 1ms.  However, these packets are completely unrelated, and this in itself is mostly meaningless.  The item with meaning is the time between packets 1 and 3 (and 2 and 4).  These are both 2ms.  Zooming into the conversation, you would see ONLY packets between the two nodes/ports, so Delta Time (displayed) is identical to conversation time.

Personally, I always use the Conversation Filter, so that I can look at just ONE conversation at a time.  This gives me both context and timings together.  When I see a huge jump in the timings, I then remove the filter and see if something else came into the server that would have taken a long time (that might explain the slowness).

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
petaganayrAuthor Commented:

Thank you for the comment. I think I understood your explanation. I have a few questions:

If the time difference between two conversations is huge but consistent for, let me say, 8 hours, what do you think it is?
What do you mean by "something else came into the server that would have taken a long time?"

Thank you.
petaganayrAuthor Commented:
Great explanation. I understood it believe it or not, it just took me a while because I'm new to analyzing WireShark data. Thank you for the explanation.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Network Analysis

From novice to tech pro — start learning today.