On Mar 12, 2009, at 8:15 PM, Chris Henderson wrote:
I am running wireshark/ ethereal version 1.0.4 on Linux. My only
network interface is eth0 and when I start a live capture on eth0, it
stops capturing any packet after a while. It's hard to say when it
actually stops the capture as it's quite random. It doesn't give any
error, just sits there not capturing anything; although in the bottom
panel I can see: eth0: live capture in progress message. I have over
10GB disk space in my /tmp directory.
Is dumpcap still running when packets stop arriving?
What happens if you try running dumpcap, or tcpdump, from a terminal
window? Does it also stop seeing packets after a while?
Are you using ring buffers?