This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hello.

We had used Wireshark 1.2.6 with a ring buffer to get traces for 72 hours. Yesterday, I installed a newer version of Wireshark on a WinXP machine. A shortcut to Wireshark was put in the autorun folder for XP. The shortcut command looks like this:

C:\Program Files\Wireshark\wireshark.exe -C "EM02" -b duration:1800 -b files:144 -B 20 -f "ether host 08:00:06:01:60:02" -i 1 -k -n -w \\Server61\Traces\EM02 -y EN10MB

The profile "EM02" is the standard profile. Only the Capture Info dialog is hidden.

Everything works great, but I'm a little bit confused about the behavior of Wireshark after the first file is written, after 30 minutes, and when the next file starts.

  • In the old version (1.2.6), the Wireshark icon stayed green. Now, it turns back to blue.
  • The buttons for start capture and options couldn't be used and stayed gray. Now, they can be used and look normal.
  • The buttons for stop and restart capture were useable. Now, they become unusable and turn to gray.

It looks like Wireshark has stopped the capture, but in the deepest rows, there is still the message < live capture in progress > to file..., and the packet counter still increases.

Wireshark still works correctly despite these false GUI indications... ;-) Any ideas how to workaround this?

Thanks, Armin

asked 22 Sep '11, 00:27

P3F's gravatar image

P3F
1111
accept rate: 0%

edited 24 Sep '11, 15:48

helloworld's gravatar image

helloworld
3.1k42041

Doesn't sound right. What version of Wireshark are you using now?

(22 Sep '11, 02:46) Jaap ♦

As a side note, you might want to consider using dumpcap instead of Wireshark for lengthy capture sessions.

(22 Sep '11, 07:00) cmaynard ♦♦

Wireshark works fine, just try to use the updated version .....(1.6.2)

permanent link

answered 28 Sep '11, 04:59

flashkicker's gravatar image

flashkicker
109131919
accept rate: 41%

Hi Flashkicker.

I forgot to wrote that I installed the actual 1.6.2 Version, sorry.

(11 Oct '11, 23:58) P3F
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×254
×53
×46

question asked: 22 Sep '11, 00:27

question was seen: 2,516 times

last updated: 12 Oct '11, 10:09

p​o​w​e​r​e​d by O​S​Q​A