As a busy network admin, you have likely peered deeply into the data flowing throughout your network in order to locate the cause of problems. I just wanted to post a quick blog that I find useful in correlating the information from my debug outputs on my Cisco devices with packet captures performed using Wireshark.
On a Cisco IOS device, the timestamps can be modified to your liking with the service timestamps option. If you are not familiar with it, feel free to type service timestamps ? to investigate further. The gist is you can set the timestamps for both your log messages and your debug output. When you want to correlate the capture in Wireshark with the information contained in a debug output, here is a sweet tweak you can make in Wireshark.
For comparison, figure 1 shows how the Wireshark output appears with default settings:
To modify how the time appears, click the View menu option, then Time Display Format. I show it in figure 2:
You see all the choices at your disposal here. If I have set the time zone on my Cisco device, then I can match that choice as shown. What I like to do is set the display to Nanoseconds together with Date and Time of Day. I show the results of that selection in figure 3:
Once again, I like to make the timestamp output match when I am troubleshooting because it makes it so much easier to correlate data from multiple sources. If this reduces the time spent for even one reader then it will be worth it. Unless you get paid by the hour.
If you have any comments or suggestions, please feel free to post them.
Until next time….