This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

We are having an intermittent issue where clients cannot access a config file on the DB server. I would like to set up Wireshark (v2.0.4) to continually capture because of the randomness of the occurrences. Is there a way to set up a capture that will auto delete the trace files so that they don't fill up a drive while continuously capturing?

asked 20 Jun '16, 06:32

jaysack's gravatar image

jaysack
6112
accept rate: 0%

edited 20 Jun '16, 08:23

Bill%20Meier's gravatar image

Bill Meier ♦♦
3.2k1850


Yes, you'll have to look at dumpcap, the capture engine, and feeding it '-b' options to setup a ring buffer. Once you've identified a time where problems occurred pick up that capture file and analyze it. So you'll have a tradeoff between storage size needed vs reaction time to retrieve the capture before it's removed.

permanent link

answered 20 Jun '16, 06:50

Jaap's gravatar image

Jaap ♦
11.7k16101
accept rate: 14%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×36
×26
×3

question asked: 20 Jun '16, 06:32

question was seen: 1,106 times

last updated: 20 Jun '16, 08:23

p​o​w​e​r​e​d by O​S​Q​A