Wireshark mailing list archives

Re: tshark memory


From: "Anders Broman" <a.broman () telia com>
Date: Tue, 19 Jan 2010 22:40:08 +0100



-----Ursprungligt meddelande-----
Från: wireshark-users-bounces () wireshark org
[mailto:wireshark-users-bounces () wireshark org] För Guy Harris
Skickat: den 19 januari 2010 22:07
Till: Community support list for Wireshark
Ämne: Re: [Wireshark-users] tshark memory


On Jan 19, 2010, at 12:57 PM, Abhijit Bare wrote:

After 2 hours, my tshark process is using 3.6G RESIDENT memory and ~ 500G
VIRT memory in top output.

To quote my reply:

When it reassembles fragmented/segmented/etc. packets, however, the
content of the reassembled packets *is* kept in memory.

Other data structures that maintain state are also kept in memory.

What version on which platform? Some work to reduce memory usage and
Speed up filtering has been done in the development version you may want to
try that out. Although 2.5 TB is most probably to much depending on the
Type of traffic captured and if reassembly is turned of or on.
Regards
Anders
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
 
mailto:wireshark-users-request () wireshark org?subject=unsubscribe

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe


Current thread: