Wireshark-bugs: [Wireshark-bugs] [Bug 1591] dumpcap in ring buffer mode. overflow
Date: Wed, 16 May 2007 12:51:33 +0000 (GMT)
http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1591


jaap.keuter@xxxxxxxxx changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|NEW                         |RESOLVED
         Resolution|                            |FIXED




------- Comment #4 from jaap.keuter@xxxxxxxxx  2007-05-16 12:51 GMT -------
Thanks for the information. From what you state I can confirm my analysis and
solution. You can download the latest build from
http://www.wireshark.org/download/automated/win32/ and use that dumpcap.

Analysis:
>From the time perspective:
2 hours (=7200s) for 100000 files.
100000/7200 = 14 files/second.

>From the throughput perspective (without capture file overhead):
200 Mb/s = 26 MB/s
26/5 = 5 files/second

Anyway you look at it, you have more than one capture file per second. This
means that the high volume vs. small capture file is applicable and thus the
single capture file phenomenon explained.


-- 
Configure bugmail: http://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.