Wireshark mailing list archives

tshark or dumpcap ring buffer limitations


From: Joseph Laibach <jlaibach () schonfeld com>
Date: Wed, 19 May 2010 13:38:23 -0400

All,
                I'm running a continuous capture of data. I'm trying to use a ring buffer of 25000 files with an 8mb 
file size. The problem is that the ring buffer starts overwriting after 10000 files. I've tried it with dumpcap and 
tshark. The command is using the -b files:25000 -b filesize:8192. Is there a limitation to the size of the ring buffer 
for dumpcap and/or tshark?

Thanks

Joe

- Wireshark V1.2.8
- Windows 2003 Server R2 64bit
- WinPcap v4.1.1




This communication is for informational purposes only.  It is not intended as an offer or solicitation or as an 
official confirmation.  Market prices and other information are not guaranteed as to completeness or accuracy and are 
subject to change without notice.  Schonfeld Group reserves the right to monitor and review the content of all messages 
sent to or from this e-mail address.
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe

Current thread: