wireshark didn't follow the timezone of my system
my timezone is UTC+08:00
but wireshark didn't follow the timezone of my system,just display time of utc
my timezone is UTC+08:00
but wireshark didn't follow the timezone of my system,just display time of utc
Wireshark looks for the TZ environment variable to use as a timezone, this will overrule the system setting. Do you by any chance have a TZ variable on your system?
sake@MacAir13:~/_tmp$ tshark -ta -c 1 -r c.pcap
1 04:46:52.951583 117.149.20.209 → 124.239.228.16 TCP 68 61042 → 80 [SYN] Seq=0 Win=42340 Len=0 MSS=1460 SACK_PERM=1 WS=2048
sake@MacAir13:~/_tmp$ TZ=Europe/Dublin tshark -ta -c 1 -r c.pcap
1 03:46:52.951583 117.149.20.209 → 124.239.228.16 TCP 68 61042 → 80 [SYN] Seq=0 Win=42340 Len=0 MSS=1460 SACK_PERM=1 WS=2048
sake@MacAir13:~/_tmp$ TZ=Europe/Athens tshark -ta -c 1 -r c.pcap
1 05:46:52.951583 117.149.20.209 → 124.239.228.16 TCP 68 61042 → 80 [SYN] Seq=0 Win=42340 Len=0 MSS=1460 SACK_PERM=1 WS=2048
sake@MacAir13:~/_tmp$
Also: if the TZ is set to a value that is not understood or invalid, the system will treat this as it was set to UTC.
TIL!
Hmmm... I would expected it to default back to the timezone from the system settings. Good to know, thanks!
6@18:48:22#xiakai1@tp/download> /cygdrive/d/program/wireshark/tshark -ta -c1 -r 21478.pcap 1 10:13:10.592133 10.21.239.12 → 10.21.239.12 TCP 68 21478 → 800 [SYN] Seq=0 Win=43690 Len=0 MSS=65495 SACK_PERM WS=2048 6@18:48:36#xiakai1@tp/download> TZ=ASIA/Shanghai /cygdrive/d/program/wireshark/tshark -ta -c1 -r 21478.pcap 1 10:13:10.592133 10.21.239.12 → 10.21.239.12 TCP 68 21478 → 800 [SYN] Seq=0 Win=43690 Len=0 MSS=65495 SACK_PERM WS=2048 6@18:48:57#xiakai1@tp/download> TZ=Europe/Dublin /cygdrive/d/program/wireshark/tshark -ta -c1 -r 21478.pcap 1 10:13:10.592133 10.21.239.12 → 10.21.239.12 TCP 68 21478 → 800 [SYN] Seq=0 Win=43690 Len=0 MSS=65495 SACK_PERM WS=2048 6@18:49:19#xiakai1@tp ... (more)
To enter a block of code:
Comments
How about just a screenshot, rather than a movie, so we don't have to pause the movie to see what's happening?
TZ is Asia/Shanghai
timestamp is 1671250750 time should be 2022-12-17 12:19:10 not 2022-12-17 04:19:10