How to find out the packet numbers where TCP connection establishment is seen?

I have filtered the TCP connections on wireshark. But there are a lot of connections with my IP address.
So how do I find out which one is to be used? Also what is the unit of time in wireshark?

This will help you :slight_smile:

Sir, I have filtered out the TCPs. But there are so many TCPs. How would I know which one to take?

Go through these links bro, it might help


https://osqa-ask.wireshark.org/questions/26174/filter-for-detecting-the-third-packet-in-a-3-way-handshake

See the flags involved in a tcp handshake. Then filter tcp for port and then look for the flags that you earlier saw in a tcp handshake. Ps: port 8081 is not used for data transfer by ftp. So please look for the right one.

Look online for how to filter for a port for tcp connection

finally got it thanks