Wireshark mailing list archives
Re: Packet Size limited during capture message
From: "Maynard, Chris" <Christopher.Maynard () GTECH COM>
Date: Thu, 29 Apr 2010 12:22:33 -0400
Thanks Steve! BTW, I had opened a bug report for this, so if you/Bill/whoever might do any more work on this, then maybe you want to track it there? Or close the bug if there's nothing else of interest to display? One other thing I thought of though, which might be nice to know, is the endianness of the libpcap file. One reason might be to know if it's the same as the host or not. If it doesn't match the host-endianness, then it would probably take longer to process since byte-swapping would be needed. If it was a really big file, then one might want to save the file in the native endianness so as to possibly speed up the processing. I have not done any profiling to know how much time would be saved or at what size capture file it would be worth doing, but obviously this would be potentially more useful the larger the file is. The magic # could be used to determine the endianness. This isn't particularly important to me (at the moment), but it's just a thought in case others think it might be useful or care to do any profiling. Knowing the endianness and whether it matches the host's would be the first step though. Here's the bug report: https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4612 - Chris -----Original Message----- From: wireshark-dev-bounces () wireshark org [mailto:wireshark-dev-bounces () wireshark org] On Behalf Of Stephen Fisher Sent: Thursday, April 29, 2010 2:32 AM To: Developer support list for Wireshark Subject: Re: [Wireshark-dev] Packet Size limited during capture message On Mon, Mar 22, 2010 at 11:32:07AM -0400, Maynard, Chris wrote:
Too bad the snaplen information isn't available through capinfos, but you can find out the snaplen via Wireshark's Statistics -> Summary window, listed as "Packet size limit".
Ask and ye shall receive as of SVN revision 32594... (http://anonsvn.wireshark.org/viewvc?view=rev&revision=32594) File name: /Users/sfisher/captures/misc.pcap File type: Wireshark/tcpdump/... - libpcap File encapsulation: Ethernet Packet size limit: 65535 bytes Number of packets: 27 :) -- Steve CONFIDENTIALITY NOTICE: The contents of this email are confidential and for the exclusive use of the intended recipient. If you receive this email in error, please delete it from your system immediately and notify us either by email, telephone or fax. You should not copy, forward, or otherwise disclose the content of the email. ___________________________________________________________________________ Sent via: Wireshark-dev mailing list <wireshark-dev () wireshark org> Archives: http://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev mailto:wireshark-dev-request () wireshark org?subject=unsubscribe
Current thread:
- Re: Packet Size limited during capture message Stephen Fisher (Apr 28)
- Re: Packet Size limited during capture message Maynard, Chris (Apr 29)
- Re: Packet Size limited during capture message Stephen Fisher (Apr 29)
- Re: Packet Size limited during capture message Guy Harris (Apr 29)
- Re: Packet Size limited during capture message Stephen Fisher (Apr 29)
- Re: Packet Size limited during capture message Maynard, Chris (Apr 29)