Opening a file, close, and save

This first section has many choices for locating and opening files so you can begin your analysis:

  • Open will launch a dialog box that will allow you to select any file; it'll go to the location of that file and allow you to select that file.
  • Open Recent will list the recently accessed files.
  • Merge will allow you to merge a file with the capture you have open. When merging, it's important that the time values are synchronized, as that is what Wireshark uses to merge the two files.
  • Import from Hex Dump is convenient when someone has sent you a hex dump from another device for analysis. The import dialog box will step through selecting the appropriate choices when importing the file.
  • Close will close the current capture. Prior to closing, Wireshark will ask you if you'd like to save the file.
  • Save allows you to save the current file. This would be useful if you have added comments or modified the file and want to preserve the changes.
  • Save As allows you to save the file as something other than the default extension, .pcapng. Once in the dialog box, you can select from the many different file formats that Wireshark has available.
  • File Set offers the ability to work with a set of files. For example, if you're doing a firewall ruleset and you're going through a whole month of files, you can work through the list one by one.

 This next File menu section takes a look at the many ways to export parts of a capture.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.119.172.146