I found that in the PCAP file we loose something. If you run fw monitor on the screens you can see how things are picked up internally.
The first (i) will be part of the performance pack. And then you get a second (i) on the actual core that picks up the packet. On TCP this is only on the SYN packet. But on UDP this happens a lot more.
It would be cool if fw monitor could be enhanced to put this information into comments if you use pcapng as output format.
Who should we buy strooopwafels to get this into a future version?
<< We make miracles happen while you wait. The impossible jobs take just a wee bit longer. >>