Wireshark-users: Re: [Wireshark-users] tshark packets droppped
From: Forthofer Russ <Russ.Forthofer@xxxxxxxxx>
Date: Thu, 7 Jan 2010 13:58:10 -0500
David wrote:
>> When I run tshark sometime I get  "xxxx packets dropped" at the end of
>> the session.    Does this mean the wireshark is dropping the packets
>> or the capture NIC is overrun or something else?

>And Jeff replied:
>It means the NIC received the packets but the capturing mechanism (libpcap + Wireshark) couldn't keep up.
>
>You might want to try capturing with 'dumpcap' instead to see if it can keep up with your traffic rate.


Does this mean that dumpcap is more efficient than tshark?  I've never understood the difference between the two programs.  Does one have functions the other does not?

The information contained in this e-mail and any accompanying documents is intended for the sole use of the recipient to whom it is addressed, and may contain information that is privileged, confidential, and prohibited from disclosure under applicable law. If you are not the intended recipient, or authorized to receive this on behalf of the recipient, you are hereby notified that any review, use, disclosure, copying, or distribution is prohibited. If you are not the intended recipient(s), please contact the sender by e-mail and destroy all copies of the original message. Thank you.