nRF52840 dongle as a sniffer to capture BLE packets in Wireshark.

I am using an nRF52840 dongle as a sniffer to capture BLE packets in Wireshark. Recently, I’ve noticed that the captured files are approximately half the expected size, and I’m not sure what is causing this issue.

This setup has been very reliable for the past two and a half years, and I haven’t made any significant changes to my configuration.

Has anyone experienced a similar issue or have any suggestions on what might be causing this?

Parents
  • Hi

    This always occurs on your side now, no matter what traffic you are sniffing? Or does it for example only occur on encrypted connections, maybe the missing data is from an encrypted advertisement or similar that you can't see without being in on the encryption. Do you have the .pcapng file of the sniffer trace instead, as that is much easier to review than the .csv file. From the .csv file I don't see anything obvious missing, but then again I don't know what you're expecting between the events here. 

    Best regards,

    Simon

Reply
  • Hi

    This always occurs on your side now, no matter what traffic you are sniffing? Or does it for example only occur on encrypted connections, maybe the missing data is from an encrypted advertisement or similar that you can't see without being in on the encryption. Do you have the .pcapng file of the sniffer trace instead, as that is much easier to review than the .csv file. From the .csv file I don't see anything obvious missing, but then again I don't know what you're expecting between the events here. 

    Best regards,

    Simon

Children
Related