Distinguish I/O Graph Bucket Totals From a Traffic Rate
Graph screenshots often reach a reviewer without the settings needed to interpret them. Before accepting a comparison, ask the author to define the quantity and time period being reported.
In Wireshark 4.6.9, open an authorised saved capture and choose Statistics, I/O Graphs. Keep the graph filter unchanged.
Separate a total from its denominator
For Y Axis options Packets, Bytes or Bits, the ordinary value is the interval total. Avg over Time converts it to a rate; choose Bits for bits per second. Record Interval and leave Y Axis Factor at one.
A two-second bucket containing 2,000 packet bytes totals 16,000 bits, averaging 8,000 bits per second. The denominator accounts for the difference.
Calculate your sample’s expected total and rate independently, keeping the same packet set and unit while testing averaging.
Make comparisons reproducible
For a report, include the capture name, graph filter, interval, unit and averaging state beside the figure. If someone supplies only an image, request those settings before treating its peak as comparable to another result.
Agree the reporting question with the person requesting the comparison. For example, an incident review might need an observation for one documented time window. Preserve that request with the evidence so a visually attractive graph does not quietly replace the original question.
Captured packet bits do not automatically measure application goodput or physical link capacity. Accept the graph only with its unit, denominator and selection stated.
Sources: Wireshark official guide; Wireshark stable 4.6.9 documentation.