Wireshark-users: Re: [Wireshark-users] Sniffing1GigE interfaces without laptop crashing
From: Kevin Cullimore <kcullimo@xxxxxxxxxx>
Date: Sun, 20 Nov 2011 23:12:28 -0500
On 11/20/2011 5:35 PM, Guy Harris wrote:
On Nov 20, 2011, at 2:15 PM, Kevin Cullimore wrote:

in either case, no reason NOT to use dumpcap/tcpdump/windump for these purposes . . .
As long as it's "capture and then look at it later" (which is probably the case if you're capturing full-on GigE), yes.
Fair enough. It's been a while since I've dealt with a "non-look-at-it-later" scenario.

However, if it's a kernel panic, the issue may have nothing to do with whether you're watching the traffic while you're capturing it, and may pop up even with a relatively simple userland network->file code path, or with a faster CPU, or....
___________________________________________________________________________
Sent via:    Wireshark-users mailing list<wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
              mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe