Wireshark-users: [Wireshark-users] tshark or dumpcap ring buffer limitations
From: Joseph Laibach <jlaibach@xxxxxxxxxxxxx>
Date: Wed, 19 May 2010 13:38:23 -0400

All,

                I’m running a continuous capture of data. I’m trying to use a ring buffer of 25000 files with an 8mb file size. The problem is that the ring buffer starts overwriting after 10000 files. I’ve tried it with dumpcap and tshark. The command is using the –b files:25000 –b filesize:8192. Is there a limitation to the size of the ring buffer for dumpcap and/or tshark?

 

Thanks

 

Joe

 

- Wireshark V1.2.8

- Windows 2003 Server R2 64bit

- WinPcap v4.1.1

 




This communication is for informational purposes only.  It is not intended as an offer or solicitation or as an official confirmation.  Market prices and other information are not guaranteed as to completeness or accuracy and are subject to change without notice.  Schonfeld Group reserves the right to monitor and review the content of all messages sent to or from this e-mail address.