so, that means no way to just get attr information without capturing
the whole data? is there a filter I can setup while capturing?
On Thu, Feb 18, 2010 at 9:09 PM, Guy Harris <guy@xxxxxxxxxxxx> wrote:
>
> On Feb 18, 2010, at 5:56 PM, Mag Gam wrote:
>
>> This works, is there a way to reduce the size of my dump? Basically, I
>> just want these stats but really not the data.
>
> Which stats do you want?
>
> If you want the names of the files being referred to, you *need* the data, so that the file names and file handles are in the capture!
>
> Note that snoop, by default, *does* capture the full packet, so that, for example, the lookups included the file name arguments:
>
> 11 0.00033 tarsus -> inchun NFS C LOOKUP2 FH=FA14 data2
>
> ...
>
> 15 0.00035 tarsus -> inchun NFS C LOOKUP2 FH=FA14 data1
> ___________________________________________________________________________
> Sent via: Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
> Archives: http://www.wireshark.org/lists/wireshark-users
> Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
> mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe
>