Ask Your Question

MultiGig Throughput Testing - Wireshark Crashes

asked 2023-01-20 19:34:22 +0000

We are doing some multigig testing and I was hoping to get some wireshark captures for TCP and UDP packets. However once we start throwing the high throughput at wireshark it crashes almost instantly. Is there someway to capture this data?

edit retag flag offensive close merge delete

2 Answers

Sort by ยป oldest newest most voted

answered 2023-01-20 21:03:59 +0000

Guy Harris gravatar image

If you can get a stack trace for the crash, please report it on the Wireshark issues list. Wireshark may not be able to keep up with a rapid stream of packets, but crashing (as opposed to, for example, dropping packets, or having the display lag behind the arriving packets) is not a valid response to such a stream.

edit flag offensive delete link more

answered 2023-01-20 20:25:35 +0000

Jaap gravatar image

updated 2023-01-20 20:26:18 +0000

You are confusing Wireshark, the protocol analyser, with a capture engine. Even though Wireshark allows you to interact with one through its user interface, it doesn't mean Wireshark is meant for such high demand capture performance.

So, what capture engines are there? As said, under the hood Wireshark uses dumpcap as its capture engine. A more common capture engine is tcpdump. For real high performance capture you may need to resort to ntopng, or specialised capture hardware solutions.

edit flag offensive delete link more

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower


Asked: 2023-01-20 19:34:22 +0000

Seen: 104 times

Last updated: Jan 20