For the sake of future reference, I just ran a single capture test, FWIW, with tcpdump. It was able to write a file size larger than 2Gs on a 32-bit Debian system.
Shehjar Tikoo wrote: > I've seen a few posts in wireshark-users archive where Ulf Lamping > mentions incorporating support for gint64 offsets for traffic dump files. > > Does this imply that tshark can write pcap files using large file > support on Linux without the need to resort to multiple capture ring > files? _______________________________________________ Wireshark-dev mailing list Wireshark-dev@wireshark.org http://www.wireshark.org/mailman/listinfo/wireshark-dev