8.4. Conversations

A network conversation is the traffic between two specific endpoints. For example, an IP conversation is all the traffic between two IP addresses. The description of the known endpoint types can be found in Section 8.5, “Endpoints”.

8.4.1. The “Conversations” window

The conversations window is similar to the endpoint Window. See Section 8.5.1, “The "Endpoints" window” for a description of their common features. Along with addresses, packet counters, and byte counters the conversation window adds four columns: the time in seconds between the start of the capture and the start of the conversation ("Rel Start"), the duration of the conversation in seconds, and the average bits (not bytes) per second in each direction.

Figure 8.3. The "Conversations" window

wsug_graphics/ws-stats-conversations.png

Each row in the list shows the statistical values for exactly one conversation.

Name resolution will be done if selected in the window and if it is active for the specific protocol layer (MAC layer for the selected Ethernet endpoints page). Limit to display filter will only show conversations matching the current display filter.

The Copy button will copy the list values to the clipboard in CSV (Comma Separated Values) or YAML format. The Follow Stream… button will show the stream contents as described in Figure 7.1, “The “Follow TCP Stream” dialog box” dialog. The Graph… button will show a graph as described in Section 8.6, “The "IO Graphs" window”.

Conversation Types lets you choose which traffic type tabs are shown. See Section 8.5, “Endpoints” for a list of endpoint types. The enabled types are saved in your profile settings.

[Tip]Tip

This window will be updated frequently so it will be useful even if you open it before (or while) you are doing a live capture.