Wireshark-users: Re: [Wireshark-users] network monitor 3.4 traces cannot be read
From: "Gianluca Varenni" <gianluca.varenni@xxxxxxxxxxxx>
Date: Thu, 22 Jul 2010 12:39:11 -0700


--------------------------------------------------
From: "Guy Harris" <guy@xxxxxxxxxxxx>
Sent: Thursday, July 22, 2010 12:21 PM
To: <stefaan.pouseele@xxxxxxxxx>; "Community support list for Wireshark" <wireshark-users@xxxxxxxxxxxxx>
Subject: Re: [Wireshark-users] network monitor 3.4 traces cannot be read


On Jul 22, 2010, at 12:01 PM, Stefaan Pouseele wrote:

attached you'll find a sample capture taken with Microsoft Network Monitor
3.4.

Works fine for me, with an SVN build of version 33612, on an x86-64 machine, built on OS X 10.6 with GCC; it's a bunch of HTTP traffic. I'm assuming it's not working for you, i.e. you can't read that capture. (We need captures from NM 3.4 that Wireshark *can't* read; I just did a capture with NM 3.4, and the version of Wireshark that was able to read your file was also able to read that file, so it is *definitely* not the case that recent Wiresharks from the trunk cannot read *any* NM 3.4 traces.)

I would also wonder if a capture made with NM 3.4 on XP is different than one on Vista/7. I'm pretty confident that the two OSes use different NM drivers.

Have a nice day
GV

What SVN version are you using, and on what type of processor and OS are you trying to read it? (Note that 1.4.0rc1 definitely will have problems reading some NetMon captures, as will 1.3.x builds; the fixes I checked in were done after 1.4.0rc1 was built.)
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users

mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe