Wireshark-dev: Re: [Wireshark-dev] How to find duplicate packets with time interval less than 2

From: "Luis EG Ontanon" <luis@xxxxxxxxxxx>
Date: Fri, 28 Nov 2008 13:42:57 +0100
On Fri, Nov 28, 2008 at 10:43 PM, Petr Janata <janata@xxxxxx> wrote:
> What is a parameter for the time window?
I mean:

Instead of giving it a fixed 2ms time window to look for duplicates
make that a parameterizable value.

 Plus, argument parameters are one letter only and the letter "i" is
already used (for (i)nterface), the "w" is taken too (for
(w)ritefile). I'd add this param/feature as a "W" for duplicate time
(W)indow.

e.g.
$ dumpcap ... -d -W 15
for 15ms

Good work, This is a very useful feature IMHO.

>
> Petr
>
> Luis EG Ontanon napsal(a):
>> The issue there is that you'll need a buffer whose size is
>> indeterminate (you can get way more than 4 packets in 2ms).
>>
>> So the buffer should adjust.
>>
>> BTW if you add a parameter for the time window it would be certainly
>> more useful.
>>
>>
>>
>
> _______________________________________________
> Wireshark-dev mailing list
> Wireshark-dev@xxxxxxxxxxxxx
> https://wireshark.org/mailman/listinfo/wireshark-dev
>



-- 
This information is top security. When you have read it, destroy yourself.
-- Marshall McLuhan