Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] Live capture stops suddenly

From: Chris Henderson <henders254@xxxxxxxxx>
Date: Wed, 18 Mar 2009 16:42:51 +1100
On Wed, Mar 18, 2009 at 3:04 PM, Guy Harris <guy@xxxxxxxxxxxx> wrote:
>
> On Mar 17, 2009, at 8:55 PM, Chris Henderson wrote:
>
>> On Sat, Mar 14, 2009 at 2:09 PM, Guy Harris <guy@xxxxxxxxxxxx> wrote:
>>>
>>> On Mar 12, 2009, at 8:15 PM, Chris Henderson wrote:
>>>
>>> Is dumpcap still running when packets stop arriving?
>>
>> I started dumpcap after wireshark stopped capturing and dumpcap
>> staretd capturing packets.
>
> Wireshark doesn't capture traffic itself - it runs dumpcap to do so.
>
> If you run Wireshark to do a capture, and it stops capturing traffic,
> is the dumpcap that it started still running?
>
>>> What happens if you try running dumpcap, or tcpdump, from a terminal
>>> window?  Does it also stop seeing packets after a while?
>>
>> dumpcap stops after a while as well.

I started dumpcap and wireshark at the same time. After a while they
both stopped capturing packets.

> What about tcpdump?

I ran tcpdump for two days and there is no such issue.