Wireshark-users: Re: [Wireshark-users] Capturing stops although there is still network traffic
Am Mittwoch 18 März 2009 19:03:44 schrieb Guy Harris:
> On Mar 18, 2009, at 4:12 AM, Michael Naugk wrote:
> > I did some tests with ps and realized that the state of process
> > dumpcap
> > switches between S and R. Might that be a hint?
>
> I.e., once packets stop showing up, dumpcap is in state R?
Actually not, I can not make a rule from that. sometimes is is in state R, but
continues capturing. sometimes in state S and stopped (maybe I don't see the
R, because I call ps every second)
Do you think this is a pcap or wireshark problem?
Anything else I can try?
tcpdump works fine, is there a way to use it for capturing in wireshark? At
the moment I capture with tcpdump and open the file in wireshark.
Kind Regards,
Michael
>
> If so, there might be some loop it's stuck in, so that it's spinning
> rather than reading captured packets.
>
___________________________________________________________________________
> Sent via: Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
> Archives: http://www.wireshark.org/lists/wireshark-users
> Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
>
> mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe