Wireshark-dev: Re: [Wireshark-dev] [Spam] to start capturing externally
Date: Thu, 14 Jun 2007 15:55:06 +0530

One more problem is ... i cant use command line options because command line options require me to give stop condition in advance like stop after 10 sec etc........but i want to stop it dynamically when i want

Phillip Paradis <[email protected]>
Sent by: [email protected]

06/14/2007 12:24 PM

Please respond to
Developer support list for Wireshark <[email protected]>

"Developer support list for Wireshark <[email protected]>"        , <[email protected]>
Re: [Wireshark-dev] [Spam]  to start capturing externally

If you simply need to capture to a file for later analysis, you could simply invoke tshark or dumpcap with the appropriate command-line options to start capturing, and either use the appropriate options to stop capturing after a certain time/amount, or simply kill the process (I would imagine SIGINTR would work on *nix, not sure how to semi-cleanly terminate under Win32; TerminateProcess would work, though pending writes might not flush correctly...)

If you absolutely need to start/stop the GUI Wireshark, you might simply locate the appropriate hWnd and post messages to it to simulate the necessary keystrokes/clicks. (This assumes you’re running Windows; if you’re on *nix of some sort, I presume X11 provides equivalent facilities, though I have no idea what they are or how to use them.)


On 6/13/07 9:43 PM, "[email protected]" <[email protected]> wrote:


I want to write an external application or interface that will give commands like start capturing and stop capturing
to the wireshark.

can anyone please help me out in this as what all are the exported methods that i can call from my application
to start and stop capturing from there.


_______________________________________________ Wireshark-dev mailing list [email protected] http://www.wireshark.org/mailman/listinfo/wireshark-dev

Wireshark-dev mailing list
[email protected]