ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-dev: Re: [Wireshark-dev] Building pruned-down version of tshark

From: Stephen Fisher <steve@xxxxxxxxxxxxxxxxxx>
Date: Tue, 26 Oct 2010 09:26:20 -0600
On Mon, Oct 25, 2010 at 11:45:29AM -0700, Tharaneedharan Vilwanathan wrote:

> I am porting wireshark to an embedded platform. I managed to 
> cross-compile wireshark (tshark, mainly) and run it on the 32-bit 
> PowerPC target. However, the executables and shared libraries take 
> about 80MB. Please see the file sizes below:

Do you need the ability to run tshark (which analyzes the packets) on 
the embedded platform or just capture packets?  Wireshark comes with 
dumpcap, which can do the capture portion without any analysis, which 
can then be moved to a general purpose computer for analysis.