ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-users: [Wireshark-users] Reading tcpdump files while still sniffing

From: Dominik Herrmann <domi@xxxxxxxxx>
Date: Sun, 09 Jul 2006 09:04:28 +0200
Hi all,

I am trying to access a tcpdump file created by
tcpdump -i /dev/eth0 -w dumpfile
with wireshark WHILE the dump is still running (and the file keeps growing).

Can wireshark "attach" to this file and report the packets as they are
written to the dumpfile?

Background: I want to set up 2-3 instances of Wireshark which read the
dumpfile but display only parts of the traffic by employing filters.

Are there other solutions?

Best regards,
Dominik