Wireshark-users: Re: [Wireshark-users] nfs attrs
From: Mag Gam <magawake@xxxxxxxxx>
Date: Thu, 18 Feb 2010 21:18:24 -0500
so, that means no way to just get attr information without capturing
the whole data? is there a filter I can setup while capturing?



On Thu, Feb 18, 2010 at 9:09 PM, Guy Harris <guy@xxxxxxxxxxxx> wrote:
>
> On Feb 18, 2010, at 5:56 PM, Mag Gam wrote:
>
>> This works, is there a way to reduce the size of my dump? Basically, I
>> just want these stats but really not the data.
>
> Which stats do you want?
>
> If you want the names of the files being referred to, you *need* the data, so that the file names and file handles are in the capture!
>
> Note that snoop, by default, *does* capture the full packet, so that, for example, the lookups included the file name arguments:
>
>        11   0.00033    tarsus -> inchun    NFS C LOOKUP2 FH=FA14 data2
>
>                ...
>
>        15   0.00035    tarsus -> inchun    NFS C LOOKUP2 FH=FA14 data1
> ___________________________________________________________________________
> Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
> Archives:    http://www.wireshark.org/lists/wireshark-users
> Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
>             mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe
>