reading pcap files with nanosecond precision
Wireshark UI displays packet arrival with nanosecond precision. libpcap uses timeval in pcap_pkthdr structure , which is returned by read pcap file routines . However timeval precision is in microseconds How can I read files and see timestamps with nsec ?
Comments
Some capture file formats support higher resolutions, e.g. ERF files from Endace.
And e.g. pcap files with a magic number of 0xA1B23C4D, which is what they're trying to read, using libpcap.
Thank you. This is helpful.