The Pcap-NG file format has support for using nano-second resolution
timestamps, and from what I understand Wireshark uses nanoseconds
internally. However, I'm not able to get Wireshark or dumpcap to write
pcapng files with nanosecond resolution. All I get is the default
microsecond timestamps.
Is there some switch or setting in Wireshark or dumpcap that I can use
in order to enable nanosecond timestamps in the output pcapng file?
/erik
--
blog: http://www.netresec.com/?page=Blog
twitter: http://twitter.com/netresec
current project: http://pcapng.com