Wireshark Timing After Filtering: Captured vs Displayed Packet Gaps
A time gap shown in Wireshark can change after filtering because the “previous displayed packet” has changed. This does not mean the capture's original timestamps changed. Decide whether you need the gap from the previous captured packet or the previous packet still visible in the filtered view.
This guide is for network administrators or support staff analysing an existing, authorised capture. If you are reporting an ordinary connection problem, start with the affected device and application, the time of the failure, the error message and whether other devices were affected. You do not need to collect or share packet contents for this first description.
Select the timing definition
Under View's time display options, choose Seconds Since Previous Captured Packet for the gap from the preceding record in the capture. Choose Seconds Since Previous Displayed Packet for the gap from the preceding record that survives the current display filter.
For example, three consecutive packets at 0.0, 0.2 and 1.0 seconds have a final captured gap of 0.8 seconds. If the middle packet is hidden, the final displayed gap is 1.0 second. Both values describe the same final packet, using different starting points.
Use the gap in the right investigation
A displayed gap is useful when the filter deliberately selects the events you want to compare. A captured gap answers a question about adjacent capture records, which may belong to unrelated traffic. Neither value alone establishes an application's response time: identify the actual request, response or other events relevant to that claim.
Keep the packet numbers, display filter and timing choice with a finding so another analyst can locate the same pair. A screenshot of a number without these details can be misleading. Preserve the original capture, and use your organisation's approved handling process because packet files may contain confidential data.
Source: Wireshark: time display formats.