Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] tshark packets droppped

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Jeff Morriss <jeff.morriss.ws@xxxxxxxxx>
Date: Thu, 07 Jan 2010 12:52:59 -0500

David wrote:
When I run tshark sometime I get  "xxxx packets dropped" at the end of
the session.    Does this mean the wireshark is dropping the packets
or the capture NIC is overrun or something else?

It means the NIC received the packets but the capturing mechanism (libpcap + Wireshark) couldn't keep up.

You might want to try capturing with 'dumpcap' instead to see if it can keep up with your traffic rate.

  • Follow-Ups:
    • Re: [Wireshark-users] tshark packets droppped
      • From: David
    • Re: [Wireshark-users] tshark packets droppped
      • From: Forthofer Russ
  • Prev by Date: Re: [Wireshark-users] Question Regarding Suspected TCP Expert Problem
  • Next by Date: Re: [Wireshark-users] tshark packets droppped
  • Previous by thread: Re: [Wireshark-users] Filter by size then export
  • Next by thread: Re: [Wireshark-users] tshark packets droppped
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation