Wireshark-users: Re: [Wireshark-users] tshark or dumpcap ring buffer limitations

From: Jaap Keuter <jaap.keuter@xxxxxxxxx>
Date: Wed, 19 May 2010 20:07:05 +0200
On 05/19/2010 07:38 PM, Joseph Laibach wrote:
All,

I�m running a continuous capture of data. I�m trying to use a ring
buffer of 25000 files with an 8mb file size. The problem is that the
ring buffer starts overwriting after 10000 files. I�ve tried it with
dumpcap and tshark. The command is using the �b files:25000 �b
filesize:8192. Is there a limitation to the size of the ring buffer for
dumpcap and/or tshark?

Thanks

Joe

- Wireshark V1.2.8

- Windows 2003 Server R2 64bit

- WinPcap v4.1.1


Hi,

That's a fixed limit:

jaap@host:~/src/wireshark/trunk$ grep RINGBUFFER_MAX_NUM_FILES *.h
ringbuffer.h:#define RINGBUFFER_MAX_NUM_FILES 10000

Thanks,
Jaap