Wireshark mailing list archives

Re: Packet Size limited during capture message


From: "Maynard, Chris" <Christopher.Maynard () GTECH COM>
Date: Thu, 29 Apr 2010 12:22:33 -0400

Thanks Steve!

BTW, I had opened a bug report for this, so if you/Bill/whoever might do any more work on this, then maybe you want to 
track it there?  Or close the bug if there's nothing else of interest to display?  One other thing I thought of though, 
which might be nice to know, is the endianness of the libpcap file.  One reason might be to know if it's the same as 
the host or not.  If it doesn't match the host-endianness, then it would probably take longer to process since 
byte-swapping would be needed.  If it was a really big file, then one might want to save the file in the native 
endianness so as to possibly speed up the processing.  I have not done any profiling to know how much time would be 
saved or at what size capture file it would be worth doing, but obviously this would be potentially more useful the 
larger the file is.  The magic # could be used to determine the endianness.  This isn't particularly important to me 
(at the moment), but it's just a thought in case others think 
 it might be useful or care to do any profiling.  Knowing the endianness and whether it matches the host's would be the 
first step though.

Here's the bug report: https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4612

- Chris

-----Original Message-----
From: wireshark-dev-bounces () wireshark org [mailto:wireshark-dev-bounces () wireshark org] On Behalf Of Stephen Fisher
Sent: Thursday, April 29, 2010 2:32 AM
To: Developer support list for Wireshark
Subject: Re: [Wireshark-dev] Packet Size limited during capture message

On Mon, Mar 22, 2010 at 11:32:07AM -0400, Maynard, Chris wrote:

Too bad the snaplen information isn't available through capinfos, but 
you can find out the snaplen via Wireshark's Statistics -> Summary 
window, listed as "Packet size limit".

Ask and ye shall receive as of SVN revision 32594...
(http://anonsvn.wireshark.org/viewvc?view=rev&revision=32594)

File name:           /Users/sfisher/captures/misc.pcap
File type:           Wireshark/tcpdump/... - libpcap
File encapsulation:  Ethernet
Packet size limit:   65535 bytes
Number of packets:   27

:)


-- 
Steve
CONFIDENTIALITY NOTICE: The contents of this email are confidential
and for the exclusive use of the intended recipient. If you receive this
email in error, please delete it from your system immediately and 
notify us either by email, telephone or fax. You should not copy,
forward, or otherwise disclose the content of the email.

___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe


Current thread: