https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7270
Jeff Morriss <jeff.morriss.ws@xxxxxxxxx> changed:
           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |jeff.morriss.ws@xxxxxxxxx
--- Comment #2 from Jeff Morriss <jeff.morriss.ws@xxxxxxxxx> 2012-05-21 08:54:29 PDT ---
As Chris indicated, Wireshark now (in 1.7.2 and later) saves not only the
displayed packets but also the packets that are necessary to dissect those
packets (the dependencies).  In this trace there is at least one http message
(frame 14) which is built up from several (frames 1-13).  If you filter and
them "Save As" only the filtered frames, you *should* get frames 1-14.  That
way when you open the new capture file Wireshark can still reconstruct the http
message.
But with this trace it's also saving a whole pile of subsequent frames which
aren't ever (AFAICS) marked as http (they're marked as bogus TDS7 messages). 
Not sure what's going on there...  Clearly there's something going wrong in the
frame-dependency logic.
-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are watching all bug changes.