Recognise Snaplen Truncation Before Trying Another Dissector
Sometimes the useful part of a packet is absent from the saved evidence. Establish whether the capture retained the needed bytes before spending time on a different protocol interpretation.
Use a copy of an authorised capture and select the packet associated with the question. Record its packet number and the exact diagnostic. A screenshot of a warning without the packet identity makes a later discussion harder to verify.
Check the retained length
Wireshark’s Packet size limited during capture message means the capture’s snapshot limit omitted part of the packet. Compare the reported original length with the captured length. If a packet was 1,500 bytes but only 96 were retained, 1,404 bytes are absent from that captured record.
Changing a display filter or Decode As cannot recreate those missing bytes. Keep truncation separate from a claim that the network lost the packet or that the selected protocol was necessarily wrong.
Record both lengths beside the packet identifier. Identify whether the question needs omitted content or can be answered from the retained headers. Keep that narrower evidence scope explicit.
Decide whether more evidence is needed
For a handover, state the unresolved question explicitly, such as whether an application field occurred in the omitted part. Do not fill that gap with the value seen in an unrelated packet merely because it would make the report look complete.
If essential content is missing, agree a suitably limited, authorised repeat collection and adequate capture length. Avoid collecting other people’s private content for a rehearsal.
Keep the original truncated file alongside any later evidence. Acceptance is an honest account of what this record retained and what remains unknown, followed by a proportionate next step when the missing information actually matters.
Sources: Wireshark official guide.