ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-dev: [Wireshark-dev] Bug with "-a duration" in tshark/dumpcap

From: "Hirsch, Christian" <Christian.Hirsch@xxxxxxxxxxx>
Date: Fri, 9 Feb 2007 08:00:15 +0100
Title: Bug with "-a duration" in tshark/dumpcap

Hi Comunity,

for traffic post analysis I used crontab to start dumpcap every 10 minutes and the options "-w $date$outname -a duration:600".

The problem is, that if there is noch traffic on the wire, the process will never be closed and hangs till it sees some IP-Packets.

This causes the machine to start every 10 minutes a new process which will never close till the machine crash because of too much processes.

The best solution would be that tshark/dumpcap writes a files and if leave it empty.
After the given duration it should be forced to stop the capture process even if there was no traffic on the wire.
Maybe somebody can support me by change the source.

Thanks in advance
Christian