Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-users: [Ethereal-users] conversations slow?

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Thoralf Will <thoralf@xxxxxxxxxxx>
Date: Tue, 15 Mar 2005 23:14:41 +0100
Hi,

to post-analyze dos/ddos attacks against our servers I've written a script that constantly checks the incoming traffic and in case of an increased packet rate/traffic count it starts a tcpdump to store the data for later investigation.

While analyzing those packets I've noticed that certain archives take a significantly longer amount of time to load the conversations screen, some even need extremely long time. DNS lookups are generally disabled, so this is not the problem.

Does a known issue with ethereal and the conversations part exist or is there anything that I can do to speed up this process? The recorded archives usually consist of chunks of 50.000 packets and the common attack is a udp-flood with huge and highly fragmented packets to fill up the bandwidth.
(Summary loads in no time and even filter rules apply are really fast.)

Thanks in advance,
Thoralf