Wireshark-users: Re: [Wireshark-users] tshark or dumpcap ring buffer limitations
From: Jeff Morriss <jeff.morriss.ws@xxxxxxxxx>
Date: Thu, 20 May 2010 13:34:54 -0400
Joseph Laibach wrote:
All,

I’m running a continuous capture of data. I’m trying to use a ring buffer of 25000 files with an 8mb file size. The problem is that the ring buffer starts overwriting after 10000 files. I’ve tried it with dumpcap and tshark. The command is using the –b files:25000 –b filesize:8192. Is there a limitation to the size of the ring buffer for dumpcap and/or tshark?

Turns out that if you specify the number of files as 0 then dumpcap/*shark will create an unlimited number of files. I don't know if that's acceptable or if you really need it to roll over at 25,000, but it's an option.