miguel olivares varela wrote:
I got the latest version of wireshark 1.0.0 over linux centos 5.1, i
try to analyze a pcap file aboout 3Gb with tshark but when i type the
following command i got an error message,
# tshark -r capture2.pcap -qz io,stat,1>>bw.out
Running as user "root" and group "root". This could be dangerous.
tshark: The file "capture2.pcap" could not be opened: Too large value for the definite type of data.
does anybody knows why?
Because, for better or worse, the code that Wireshark and TShark use to
read capture files can't handle files larger than 2GB.