I took some capture files this morning on our ASA appliance. I actually view the packets being captured with the real time command. Once I had what I needed, I ended the capture. I then FTP the trace files to my workstation, opened Wireshark to then point to the files. I keep getting this message when I try to open the files::The file "C:\FTProot\lori_ip" isn't a capture file in a format Wireshark understands. I have tried using both a .pcap and a .cap extension. I am still getting the same error message.
Wireshark is opening other files just fine.
Using the capture command, the syntax would look like this:
copy /pcap capture:[context/]
Here is a link to the command reference also:
Hope that helps.