ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-users: [Wireshark-users] Tshark shows packet loss while tcpdump doesn't! - Why?

From: H Aslam <hassan-aslam@xxxxxxxxxxx>
Date: Mon, 31 Aug 2009 19:22:55 +0200



I'm streaming a video sequence via VLC using RTP and port 1234 and I'm trying to detect packet loss, jitter and delay.

When I run the following command:

tshark -i 6 -c 5000  -d udp.port==1234,rtp -z rtp,streams

I get a lot of packet loss.

While running tcpdump and thereafter reading the pcap, generated by tcpdump, in tshark and showing the statistics I get much more reliable results with 0% packet loss.

I'm running tshark on an embedded Linux.

Why is that? - something with the filters?

How can TSHARK be tweaked to show 0 % packet loss?

Thanks in advance!


check out the rest of the Windows Live™. More than mail–Windows Live™ goes way beyond your inbox. More than messages