ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
July 17th, 2024 | 10:00am-11:55am SGT (UTC+8) | Online

Wireshark-users: [Wireshark-users] Merging HTTP packets

From: Yang Zhang <yanghatespam@xxxxxxxxx>
Date: Thu, 10 Apr 2008 22:51:41 -0400
Hi, I captured some packets with the filter "tcp port 80 and host www.facebook.com". As a result I see a bunch of individual packets - some HTTP, some just TCP, with many of the HTTP messages segmented.

I can ignore the TCP-only packets by typing in 'http' in the filter box, but is there some way to merge the HTTP packets to be whole, unsegmented requests/responses?

If wireshark is the wrong tool for this level of analysis, then are there any recommendations of a better tool?

Thanks!