Wireshark-users: Re: [Wireshark-users] Wireshark and Big Sniffs

From: Jaap Keuter <jaap.keuter@xxxxxxxxx>
Date: Tue, 20 Apr 2010 16:26:00 +0200

Hi,

These are some options:

  • Don't do the merge.
  • use Pilot (see Cace tech website http://www.cacetech.com/)
  • Visit http://wiki.wireshark.org/KnownBugs/OutOfMemory

Thanks,

Jaap

 

On Tue, 20 Apr 2010 10:24:04 +0200, <A.Fendt@xxxxxxxxxxxxxxxxxxxxxx> wrote:

Hello,
 
i’ve been capturing the whole traffic of my company. Every two hours I created a new file (ring buffer). Each file has the size of 100 – 200 Megabyte. Now I want to start a Endpoint Analyze. The first thing I made was to merge the Files to one large (10 GB).
 
If I open now the 10 GB Capture-File my Wireshark crashes every time. What should I do now?
 
Greetings
Andreas Fendt