Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] Tshark shows packet loss while tcpdump doesn't! - Why?

From: H Aslam <hassan-aslam@xxxxxxxxxxx>
Date: Mon, 31 Aug 2009 19:22:55 +0200



I'm streaming a video sequence via VLC using RTP and port 1234 and I'm trying to detect packet loss, jitter and delay.

When I run the following command:

tshark -i 6 -c 5000  -d udp.port==1234,rtp -z rtp,streams

I get a lot of packet loss.

While running tcpdump and thereafter reading the pcap, generated by tcpdump, in tshark and showing the statistics I get much more reliable results with 0% packet loss.

I'm running tshark on an embedded Linux.

Why is that? - something with the filters?

How can TSHARK be tweaked to show 0 % packet loss?

Thanks in advance!


check out the rest of the Windows Live™. More than mail–Windows Live™ goes way beyond your inbox. More than messages