Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 5254] Converted SNOOP capture file slow to read in

Date: Thu, 23 Sep 2010 11:11:44 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5254

--- Comment #2 from Jeff Morriss <jeff.morriss.ws@xxxxxxxxx> 2010-09-23 11:11:43 PDT ---
(In reply to comment #1)
> First thought as to what's happening: the file with the snapshot length will
> cause Wireshark to throw an exception for every packet.  Could exceptions be so
> expensive?

Simple testing indicates this isn't the case: chopping off the end of packets
with editcap yields faster loads with the smaller (with snapshot) file on both
Windows and Linux.

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.