On Mar 17, 2009, at 8:55 PM, Chris Henderson wrote:
On Sat, Mar 14, 2009 at 2:09 PM, Guy Harris <guy@xxxxxxxxxxxx> wrote:
On Mar 12, 2009, at 8:15 PM, Chris Henderson wrote:
Is dumpcap still running when packets stop arriving?
I started dumpcap after wireshark stopped capturing and dumpcap
staretd capturing packets.
Wireshark doesn't capture traffic itself - it runs dumpcap to do so.
If you run Wireshark to do a capture, and it stops capturing traffic,
is the dumpcap that it started still running?
What happens if you try running dumpcap, or tcpdump, from a terminal
window? Does it also stop seeing packets after a while?
dumpcap stops after a while as well.
What about tcpdump?