Wireshark mailing list archives

Re: tshark packets droppped


From: Jeff Morriss <jeff.morriss.ws () gmail com>
Date: Thu, 07 Jan 2010 12:52:59 -0500

David wrote:
When I run tshark sometime I get  "xxxx packets dropped" at the end of
the session.    Does this mean the wireshark is dropping the packets
or the capture NIC is overrun or something else?

It means the NIC received the packets but the capturing mechanism 
(libpcap + Wireshark) couldn't keep up.

You might want to try capturing with 'dumpcap' instead to see if it can 
keep up with your traffic rate.
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe


Current thread: