Wireshark-users: Re: [Wireshark-users] Continuous/circular in-memory tracing?

From: Jay Levitt <lists-wireshark@xxxxxxxxxxxxx>
Date: Sat, 22 Dec 2007 08:57:59 -0500
On 12/22/2007 8:51 AM, Sake Blok wrote:
Dumpcap does not interpret what it sees, it sole purpose in life is to
grab packets of the wire(less) and to drop them to disk. And it is quite happy to do so for you :-)

Ah, ok! Good to know - I somehow had it in my head that all the interpretation/dissection/parsing was done at display time in Wireshark.

dumpcap sounds like just the thing - and if both you guys are using it this way for this long, I should probably quit whining about disk writes and just deal with it! Premature optimization, all that.

Jay