Ethereal-users: [Ethereal-users] Help automating Historical network capture-rollover

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: "Cory Perry (SNL:434-951-7463)" <CPerry@xxxxxxx>
Date: Thu, 17 Nov 2005 09:35:40 -0500
 
 
I am looking for a way to historically keep about 2 weeks of traces for
troubleshooting network issues.

I've tried to use Ring Buffer to rollover after what I expect 2 weeks
capturing will require, but option seems to be limited to 1024 max no
matter what is set.  

I am currently testing tethereal under windows environment. I am
utilizing Windows Folder compression support to reduce data size and
files size of 300000 KB. 1024 files gets me about 292 GB uncompresses
(180 GB Compressed) in about 50 hours, about 11.5 days short of planned
requirement.

If anyone has done something similar in windows or Unix (Freebsd is my
preferred Unix solution).

Some of the issue I am working with.

300000 KB painfull to work with, and with 1024 limitation that will have
to be much larger. ;)
Compression, only have 1.6 TB for storage/rollover.
Data easily accessible from Windows environment for non-unix users.
Automated, I am forgetful and server could be rebooted for patches by
other support peolple.
Need full capture, can't filter. Don't know what might be needed.