Eliminate the gui overhead with tshark. Use the -w and -b options for longer term captures. "tshark -h" should get you started
-----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Hans Nilsson Sent: Friday, 19 January 2007 12:00 p.m. To: Community support list for Wireshark Subject: Re: [Wireshark-users] Buffers size, ring buffer and multiple files Didn't someone on this list say that Wireshark isn't primarily a capturing tool for capturing massive amounts of data, it's more on an protocol analyzer? So maybe try saving the data with another tool and the reviewing it in Wireshark. On Thu, 18 Jan 2007 12:41:09 -0800, "Chet Seligman" <[EMAIL PROTECTED]> said: > When I want to capture a very large amount of traffic, I usually set up > for > multiple files(10-20), buffer size of 64meg, new file every 64meg and > ring > buffer of up to 10 files. > > Is this the best configuration? > Does anyone have rules of thumb? > > Occasionally WS crashes in extended captures, even with much smaller > parameters. > > Chet -- Hans Nilsson [EMAIL PROTECTED] -- http://www.fastmail.fm - Same, same, but different... _______________________________________________ Wireshark-users mailing list Wireshark-users@wireshark.org http://www.wireshark.org/mailman/listinfo/wireshark-users ____________________________________________________________________ CAUTION - This message may contain privileged and confidential information intended only for the use of the addressee named above. If you are not the intended recipient of this message you are hereby notified that any use, dissemination, distribution or reproduction of this message is prohibited. If you have received this message in error please notify Air New Zealand immediately. Any views expressed in this message are those of the individual sender and may not necessarily reflect the views of Air New Zealand. _____________________________________________________________________ For more information on the Air New Zealand Group, visit us online at http://www.airnewzealand.com _____________________________________________________________________ _______________________________________________ Wireshark-users mailing list Wireshark-users@wireshark.org http://www.wireshark.org/mailman/listinfo/wireshark-users