Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] Capturing stops although there is still network traffic

From: Michael Naugk <zless@xxxxxxx>
Date: Thu, 19 Mar 2009 09:37:55 +0100
Am Mittwoch 18 März 2009 19:03:44 schrieb Guy Harris:
> On Mar 18, 2009, at 4:12 AM, Michael Naugk wrote:
> > I did some tests with ps and realized that the state of process
> > dumpcap
> > switches between S and R. Might that be a hint?
>
> I.e., once packets stop showing up, dumpcap is in state R?

Actually not, I can not make a rule from that. sometimes is is in state R, but 
continues capturing. sometimes in state S and stopped (maybe I don't see the 
R, because I call ps every second)

Do you think this is a pcap or wireshark problem?
Anything else I can try?

tcpdump works fine, is there a way to use it for capturing in wireshark? At 
the moment I capture with tcpdump and open the file in wireshark.

Kind Regards,
Michael

>
> If so, there might be some loop it's stuck in, so that it's spinning
> rather than reading captured packets.
> 
___________________________________________________________________________
> Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
> Archives:    http://www.wireshark.org/lists/wireshark-users
> Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
>             
> mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe