Wireshark captures include precise time information for each packet. By adjusting the Time Display Format, analysts can choose how this timestamp is shown, making it easier to analyze event timing, packet delays, or communication sequences.
How to Change the Time Display Format
You can switch the time format by navigating to:
View → Time Display Format
From there, choose one of several available formats, depending on what you want to analyze.
Common Time Display Formats
Format | Description |
---|---|
Date and Time of Day | Shows full timestamp with date (e.g., 2025-04-04 14:23:45.123456) |
Time Since Beginning of Capture | Shows how much time has passed since capture started |
Time Since Previous Packet | Displays delay between each packet |
Seconds Since Epoch | Shows time in UNIX timestamp format |
Time Since First Packet in Conversation | Useful for session-level analysis |