Saving and viewing comments

Once you are done adding comments, either on the entire file or a single packet, you'll see that the filename has a little asterisk in front of the name, as shown here:

Filename with an asterisk

The asterisk serves as a reminder that you have modified the capture. When you close the capture, Wireshark will prompt you to save the modified file. It's important to note that you must save in .pcapng format when using comments. 

Once you have preserved the comments, there are several ways to view the comments:

  • To see comments on a file, go to Statistics | Capture File Properties, as shown in the Capture File Properties-Web Page.pcapng screenshot.
  • To see comments on packets, go to Expert System and select Show Comments, which is on the lower right-hand side of Expert Information Console. You will then see the comments listed, as shown in the following screenshot:

Expert Information—show comments

Now, you can see how easy it is to add comments to an entire capture or a single packet. Once done, it's important to save the capture in .pcapng format, so you can view the comments at a later date.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.147.78.174