How is the Wireshark Session Feature Implemented?

  • retag add tags

The Wireshark session feature, which involves statistics and conversations, allows selecting a specific conversation as a filter. Does this simply reparse the conversation's IP address and port as filter criteria for Wireshark to display, or does it parse packet data when opening a pcap file, add the parsed information to the saved session, and directly display each packet's information within the selected conversation when the session feature is invoked?

mpy's avatar
3
mpy
asked 2024-03-28 08:20:42 +0000
edit flag offensive 0 remove flag close merge delete

Comments

There are several places in the Wireshark gui to look at "stream" data.
Is this what you mean by "session"?

Chuckc's avatar Chuckc (2024-03-28 11:42:42 +0000) edit
add a comment see more comments