Hello,
I am observing captured packets using tcpdump and I would like to clarify something regarding timestamps.
Is it normal that the capture timestamp differs from the actual packet transmission time by around 1 millisecond? I want to understand if this difference is expected due to the capture process, or if it indicates some misconfiguration or system delay.
Thank you for your guidance.