I would like to configure Wireshark to generate a file in Visual Networks format every day. Is it possible? I just plan to launch Wireshark one time. Thanks. asked 12 May '16, 14:26 puertas12 edited 12 May '16, 14:26 |
One Answer:
Firstly, for long term captures use dumpcap, as Wireshark will run out of memory at some point. Next, have a look at dumpcap's Finally, dumpcap won't write the capture in the format you've requested "Visual Networks", use editcap to post process the capture file. answered 13 May '16, 03:55 grahamb ♦ A more in-depth discussion, written by Jeremy Stretch, of what @grahamb suggests is at http://packetlife.net/blog/2011/mar/9/long-term-traffic-capture-wireshark/. (13 May '16, 06:55) coloncm |
You mean start Wireshark once, and for it to create a new capture file every day?
That is exactly what I mean