High NFS READ latency from SLES10 client to EMC Clarion filer


I have a tshark trace dump and want to see the human readable time stamps between NFS READ procedure calls/packets. I understand frame.time_delta might be a good filter expression?

Can anyone provide a command line example on how to do this running tshark. I have the RTT stats and READ procedure has very heavy latency so I want to drill down and see if I can understand which file handle(s) might be responsible.

Any help is very much appreciated.


Thank you for your response. I will use your filter and see what the results are. Thank you again.

I used the following before to get a grasp on which NFS calls were taking a lot of time:

tshark -o tcp.desegment_tcp_streams:FALSE -nlr nfs.cap -R rpc -qzio,stat,300,\

If you want to drill down, you might want to use something like:

tshark -nlr nfs.cap -R "rpc.time>0.5"

