ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
July 17th, 2024 | 10:00am-11:55am SGT (UTC+8) | Online

Wireshark-users: Re: [Wireshark-users] Capturing stops although there is still network traffic

From: Michael Naugk <zless@xxxxxxx>
Date: Mon, 16 Mar 2009 11:26:05 +0100
Hi,

thanks for the quick reply.

> Is dumpcap still running when the traffic stops arriving?

yes it is!
/usr/bin/dumpcap -i eth2 -Z none

> What happens if, for example, you try running dumpcap from the
> console, or try running tcpdump?

tcpdump seems to work

The run of dumpcap tells me about dropped frames:
# dumpcap -i eth2 -w /tmp/x
File: /tmp/x
Packets: 254945 ^CPackets dropped: 65028
# dumpcap -i eth2 -w /tmp/x
File: /tmp/x
Packets: 31 ^CPackets dropped: 18765

Any ideas why are these frames dropped?

>
> Are you using ring buffers?

No, I don't.

Kind regards,
Michael

>
> 
___________________________________________________________________________
> Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
> Archives:    http://www.wireshark.org/lists/wireshark-users
> Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
>             
> mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe