ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
July 17th, 2024 | 10:00am-11:55am SGT (UTC+8) | Online

Wireshark-bugs: [Wireshark-bugs] [Bug 12231] tshark uses ever increasing amount of memory

Date: Fri, 04 Mar 2016 14:41:01 +0000

Comment # 5 on bug 12231 from
(In reply to Alexis La Goutte from comment #4)
> Hi Matt,
> 
> you need to "capture" packet ? because the better is to use dumpcap if you
> need only to capture packet.. 
> 
> PS : also don't launch tshark with root account... it is not safe !
> 
> We can close this issue ?

I agree with Alexis in that if you only need to capture packets and aren't
really using tshark to analyze them, then it's better to use dumpcap[1];
however, if for whatever reason you do need to use tshark, then you might want
to read Evan Huus' article, "To Infinity and Beyond! Capturing Forever with
Tshark"[2].

[1]: https://wiki.wireshark.org/KnownBugs/OutOfMemory
[2]:
https://blog.wireshark.org/2014/07/to-infinity-and-beyond-capturing-forever-with-tshark/


You are receiving this mail because:
  • You are watching all bug changes.