Hi, I've been using wireshark on a laptop to count the number of people walking past with mobile phones over a weekend. I'm using a usb wifi dongle for the capture as the on board wifi chip doesn't appear to be compatible with wireshark. I use tshark within the command prompt and specify the amount of time to collect. The pcap file closes off at the correct time, however on some weekends the count appears to just stop randomly. Sometimes it's after an hour, sometimes it's after 40 hours. The lack of consistency in the problem is making troubleshooting difficult. I've tried using dumpcap instead of tshark but the count stopped after 10 minutes. I've tried a laptop with 16gb or ram rather than the 8gb in my normal laptop, but it didn't make a difference. Any ideas? Thanks. asked 15 Jun '16, 18:58 richelle |
Would you share what operating system you are using along with the USB hardware you have chosen to deploy?
With this information, troubleshooting might be possible.
Thanks Bob.
I'm running windows 10 and using the netgear A6200 USB adaptor: http://www.netgear.com.au/home/products/networking/wifi-adapters/a6200.aspx?cid=gwmng
Does this sound like it is happening to you?
https://community.netgear.com/t5/WiFi-Adapters/A6200-Disconnecting-on-Windows-10/td-p/981072
I assume you are not using monitor mode as the only way to do so with that chipset on Windows/Wireshark would be with npcap but you don't say anything about it. However, to do what you want I assume you looking for probes and/or unique MAC addresses, so you need monitor mode.
I have good better luck with PCI-based devices than USB, but end up having to USB all the time, even though the crash often. Please share a little more about your test process.
@richelle: Your answer has been converted to a comment as that's how this site works. Please read the FAQ for more information.