Read the address timeline#

Follow when each address sent or received traffic, against a packet histogram across the top of the plot.

The timeline at the bottom of the Forensic Timeline view shows an address-by-time view of the capture. Both the Network Graph and Connection Table tabs share it, and it stays visible as you switch between them.

The IP timeline with a packet histogram across the top, IP addresses listed on the left, and traffic plotted as coloured points and lines on the right

The three timeline regions#

The timeline has three regions:

  • Address list: every IP address in the capture, with a running packet count next to each.
  • Histogram: overall packet volume across the same time window.
  • Plot: one row per address, with traffic between addresses drawn as coloured points and lines over time.

Coloured dots mark when a particular address sent or received a frame. Vertical lines connect dots from related addresses, so you can read the timeline as a series of conversations rather than a per-address strip.

Read the histogram above#

Use the histogram to spot bursts and idle periods at a glance. Then follow a burst down into the per-address rows to see which addresses caused it.

A spike that lights up many rows is a wide event that affects several pairs, for example the start of a page load that fans out to many backends. A spike that lights up two rows is a single busy pair.

Highlight from the other tabs#

Select a row in the Connection Table to highlight the two endpoints in the timeline. The highlight shows exactly when that pair exchanged traffic. Select a node in the Network Graph to highlight its row in the same way.

Pan and zoom the plot#

Drag the plot horizontally to scroll through time. The X and Y zoom controls on the right edge change the scale on each axis independently. Use the X axis when you want to focus on a narrow time range. Use the Y axis when many addresses are stacked together and you need to read individual rows.

The reset icon under the zoom controls returns the plot to fit-the-capture defaults.