Wireshark captures include precise time information for each packet. By adjusting the Time Display Format, analysts can choose how this timestamp is shown, making it easier to analyze event timing, packet delays, or communication sequences.

How to Change the Time Display Format

You can switch the time format by navigating to:

View → Time Display Format

From there, choose one of several available formats, depending on what you want to analyze.

Common Time Display Formats

FormatDescription
Date and Time of DayShows full timestamp with date (e.g., 2025-04-04 14:23:45.123456)
Time Since Beginning of CaptureShows how much time has passed since capture started
Time Since Previous PacketDisplays delay between each packet
Seconds Since EpochShows time in UNIX timestamp format
Time Since First Packet in ConversationUseful for session-level analysis