Description
This article describes how to view the Date and Time on Wireshark from 'diag sniffer packet'. This can help if you need to know when the packet was captured.
Scope
FortiGate.
Solution
- Capture traffic with 'diag sniffer packet'. In this example, 2 packets will be captured with verbose 6. 'a' is timestamps the packets with the absolute UTC.
- Convert it to a PCAP file: Troubleshooting Tip: Using the FortiOS built-in packet sniffer for capturing packets
- Open the PCAP file with Wireshark.
- Select View -> Time Display Format -> Date and Time of Day.