Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-users: [Ethereal-users] Does using capture filter prevent packet drops?

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: "Lars Ruoff" <Lars.Ruoff@xxxxxxxxxx>
Date: Fri, 15 Oct 2004 17:23:19 +0200
Does using a capture filter allow capturing (an interesting part of) high
bandwidth traffic without packet drops as opposed to what would be the case
when capturing all traffic?

Hmm, i realize that the above formulation is a poor try to get it all in one
sentence. :)
Let me reformulate it:
Say the machine/OS is limited to capturing a maximum bandwidth of 10Mbit/s
without dropping packets. But the real bandwidth is close to 100 Mbit/s.
(Assume the NIC is 100MBit/s capable  of course). But the part i'm
interested in is only 5% of the overall traffic. By setting a capture
filter, will i be able to capture these 5% without packet drops?

The question is basically wether the capture filter is applied at a low
enough level to not let the packet i'm not interested in pass to a level
were it encouters system's limitations.

regards,
Lars Ruoff.