Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] Will capturing packets with tcpdump/tshark affect traffic proc

From: Rayne <hjazz6@xxxxxxxxx>
Date: Tue, 9 Aug 2016 00:57:19 +0000 (UTC)
Hi,

If I use tcpdump or tshark to capture packets on a certain interface, will it interfere with another program that is also receiving packets on that interface?

For example, I have a program that receives traffic from eth0, processes it, then forwards the traffic out to another server via eth1. If I were to run tcpdump or tshark (-i eth0) and write the packets to a file, will these packets still be received by my program? The reason I'm running tcpdump/tshark is to check if there is any dropped packet on that interface, but I don't want it to affect the processing of the traffic.

Thank you.

Regards,
Rayne