Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] tshark stop capturing after a certain amount of packets be

Date: Thu, 13 Aug 2009 21:21:39 -0700
Yes, that would be my immediate thought too, have you tried setting up a ring buffer to see if you can get past that.
 
-------- Original Message --------
Subject: Re: [Wireshark-users] tshark stop capturing after a certain
amount of packets being captured !
From: Bill Meier <wmeier@xxxxxxxxxxx>
Date: Thu, August 13, 2009 9:18 pm
To: Community support list for Wireshark
<wireshark-users@xxxxxxxxxxxxx>

Amir Najafi-Ardabili wrote:
> Hi,
>
> I am using tshark to capture packets:
>
> tshark -q
>
> I want tshark to keep capturing but unfortunately it automatically stops
> capturing after a short period of time:
>
> debian:/home/worldamity# tshark -q
>
> Running as user "root" and group "root". This could be dangerous.
>
> Capturing on eth0
>
> 36534 packets dropped
>
> 18707990 packets captured
>
> do you have any idea how to fix this problem?
>
>

Hmm.... Almost 19M packets; I'm guessing out-of-memory.

Please see http://wiki.wireshark.org/KnownBugs/OutOfMemory.


Also: please don't cross-post to multiple Wireshark lists.

Thanks !

___________________________________________________________________________
Sent via: Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives: http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
mailto:wireshark-users-request@wireshark.org?subject=unsubscribe