Wireshark监控btsnoop时报时间戳错误,无法捕获蓝牙流量
解决Android 7.1.2 LineageOS下Wireshark抓蓝牙流量的时间戳错误问题
问题场景
在监控运行LineageOS Android 7.1.2的旧安卓手机蓝牙流量时,已完成以下操作:
- 连接手机与电脑
- 启用手机端Bluetooth HCI snoop日志
- 执行
adb root获取权限
但触发蓝牙数据包发送时,Wireshark立即抛出错误:
An error occurred while writing to the file "\.\pipe\wireshark_extcap_android-bluetooth-btsnoop-net-42004ff5ca5b5300_20240530131643": We don't support writing that record's time stamp to that file type.
随后弹出提示框:
No packets captured.
As no data was captured, closing the temporary capture file.
Help about capturing can be found at
https://gitlab.com/wireshark/wireshark/-/wikis/CaptureSetupWireless (Wi-Fi/WLAN):
Try to switch off promiscuous mode in the Capture Options.
捕获进程随即停止,推测问题源于HCI snoop日志的时间戳记录格式与Wireshark不兼容。
可行解决方案
1. 改用离线抓取+本地分析的方式
实时抓包的时间戳适配问题可以通过先抓取日志再离线分析绕过:
- 保持手机端Bluetooth HCI snoop日志处于启用状态,确保
adb root权限已获取 - 触发目标蓝牙操作,让系统生成snoop日志(默认路径通常为
/sdcard/btsnoop_hci.log,部分设备可能在/data/misc/bluetooth/logs/btsnoop_hci.log) - 执行
adb pull /sdcard/btsnoop_hci.log ./将日志文件导出到本地电脑 - 直接用Wireshark打开本地的
btsnoop_hci.log文件进行流量分析
2. 降级Wireshark版本适配旧系统时间戳
新版Wireshark可能对旧Android系统的HCI时间戳格式支持不佳,尝试降级到3.x系列版本(如3.6.x稳定版),再重新进行实时抓包测试。
3. 检查系统时间与日志配置
- 确保手机系统时间与电脑时间完全同步,避免时间戳跨时区或格式不匹配的问题
- 进入手机开发者选项,查看是否有Bluetooth HCI snoop日志的格式调整选项(部分LineageOS定制版本可能提供相关设置)
内容的提问来源于stack exchange,提问作者FinW
相关产品推荐
相关产品推荐

