Time corrections


#1

When my wireshark/tcpdump host’s packet buffer fills, the arrival times of captured packets get distorted.

Can anyone tell me how to correct for this?

I have considered pinging the host’s ip address encapsulating the hi-res time as data, but would like to avoid the work if possible.