Wireshark

  • Riverbed Technology
  • WinPcap
SHARKFEST '13 - Wireshark Developer and User Conference - June 16-19, 2013 - UC Berkeley
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] Req: Information regarding wireshark file logging

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Douglas Ross <doug_ross_59@xxxxxxxxxxx>
Date: Mon, 31 May 2010 22:13:00 +0000 (GMT)

Hi,
 
Yes, of course - I did miss something!
And woke this morning with it in my head (it's now 0800 in Melbourne).
Apologies for my obtuse moment, and thanks for neat explanations.
 
As a matter of course I specified capture file location, and normally I used tethereal. Now that I'm back in the "frame" I've started using tshark.
 
Next time I'll "think before ink" :)
 
Cheers
Doug


From: Guy Harris <guy@xxxxxxxxxxxx>
To: Community support list for Wireshark <wireshark-users@xxxxxxxxxxxxx>
Sent: Tue, 1 June, 2010 6:17:06 AM
Subject: Re: [Wireshark-users] Req: Information regarding wireshark file logging


On May 31, 2010, at 6:54 AM, Douglas Ross wrote:

> I'd like to discuss a point about "temporary" files.
> 
> In my experience (Windows), ethereal/wireshark creates files in the location specified by the user (if not stdout).
> So they are "permanent".

As Jaap noted, the user doesn't have to specify a location - and, if they don't, it doesn't get written to the standard output.  (In fact, Ethereal/Wireshark never allowed the capture to be written to the standard output, and never will allow that; the capture has to exist in some form of storage as long as it's open.)

If the user doesn't specify a location, the packets are written to a file in a temporary file directory; if the user closes the capture, the file is removed.  It is a named file in the file system, so it's "permanent" in that sense, but it's removed when the capture is closed, so it's not "permanent" in that sense.
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
            mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe

 
  • References:
    • [Wireshark-users] Req: Information regarding wireshark file logging
      • From: surabhi pandey
    • Re: [Wireshark-users] Req: Information regarding wireshark file logging
      • From: Guy Harris
    • Re: [Wireshark-users] Req: Information regarding wireshark file logging
      • From: Douglas Ross
    • Re: [Wireshark-users] Req: Information regarding wireshark file logging
      • From: Guy Harris
  • Prev by Date: Re: [Wireshark-users] Req: Information regarding wireshark file logging
  • Next by Date: Re: [Wireshark-users] TCP connection is still in ESTABLISH state actually it is disconnected
  • Previous by thread: Re: [Wireshark-users] Req: Information regarding wireshark file logging
  • Next by thread: [Wireshark-users] start stop tshark
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation