It is not uncommon when using a packet broker that is getting data from taps that packets may show up "out of order" in Wireshark even though the trace extraction was done in Observer.  We receive the timestamp from the packet broker.  A workaround is to open the trace file post capture in Console/Expert and re-order them and save the pcap, then open in Wireshark.

Be the first one to comment


Please log in or sign up to comment.