Wireshark-users: Re: [Wireshark-users] Pcap file isn't a capture file in a format TShark understa
From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Sat, 23 Jan 2010 11:55:21 -0800
On Jan 22, 2010, at 10:06 AM, kahou lei wrote:

> This file is captured by another machine.

How was the file captured on that machine?  What software was used?

> I try to use tshark and wireshark with this file on another machine which is not the captured one and it works.

Are you saying that on one machine, TShark and Wireshark can read the "udp.pcap" file, but, on another machine, TShark and Wireshark cannot read the *same* "udp.pcap" file?

If so, what versions of TShark and Wireshark are running on those two machines, and, if you run the command "capinfos udp.pcap" on the machine where TShark and Wireshark *can* read the file, what does it print?