Not sure where I am going wrong with my trace analysis but I have several SMB traces and there is a lot of TCP Segment of a Reassembled PDU frames in this trace. I keep trying to use the display filter 'tcp.pdu.time' but nothing is ever displayed after typing the filter in? The WireShark display filter help page says that the field will not be added into the TCP protocol tree until the first refresh. After refreshing I still have nothing in my display. I am curious if I don't have the correct understanding of using this display filter. Or do I need to do another step first before trying to use it? Any help would be appreciated.
Kevin L. Gaudineer
Phone: (515)-241-7745
Cell: (515)-205-3069
Email: gaudinkl@xxxxxxx
********************************************
This message and accompanying documents are covered by the
Electronic Communications Privacy Act, 18 U.S.C. §§ 2510-2521,
and contain information intended for the specified individual(s) only.
This information is confidential. If you are not the intended recipient
or an agent responsible for delivering it to the intended recipient, you
are hereby notified that you have received this document in error and
that any review, dissemination, copying, or the taking of any action
based on the contents of this information is strictly prohibited. If you
have received this communication in error, please notify us immediately
by e-mail, and delete the original message.
*********************************************