Wireshark-users: Re: [Wireshark-users] nfs attrs

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Thu, 18 Feb 2010 18:09:55 -0800
On Feb 18, 2010, at 5:56 PM, Mag Gam wrote:

> This works, is there a way to reduce the size of my dump? Basically, I
> just want these stats but really not the data.

Which stats do you want?

If you want the names of the files being referred to, you *need* the data, so that the file names and file handles are in the capture!

Note that snoop, by default, *does* capture the full packet, so that, for example, the lookups included the file name arguments:

	11   0.00033    tarsus -> inchun    NFS C LOOKUP2 FH=FA14 data2

		...

	15   0.00035    tarsus -> inchun    NFS C LOOKUP2 FH=FA14 data1