Shark SE400 User's Guide Page 74

  • Download
  • Add to my manuals
  • Print
  • Page
    / 228
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 73
Capturing Live Network Data
65
The execution of BPFs can be sped up on Linux by turning on BPF JIT by executing
$ echo 1 >/proc/sys/net/core/bpf_jit_enable
if it is not enabled already. To make the change persistent you can use sysfsutils.
Manage Interfaces The Manage Interfaces button opens the Figure 4.6, “The “Add New
Interfaces” dialog box” where pipes can be defined, local interfaces
scanned or hidden, or remote interfaces added (Windows only).
4.5.2. Capture File(s) frame
An explanation about capture file usage can be found in Section 4.11, “Capture files and file modes”.
File This field allows you to specify the file name that will be used
for the capture file. This field is left blank by default. If the field
is left blank, the capture data will be stored in a temporary file.
See Section 4.11, “Capture files and file modes” for details.
You can also click on the button to the right of this field to
browse through the filesystem.
Use multiple files Instead of using a single file Wireshark will automatically
switch to a new one if a specific trigger condition is reached.
Use pcap-ng format This checkbox allows you to specify that Wireshark saves
the captured packets in pcap-ng format. This next generation
capture file format is currently in development. If more than
one interface is chosen for capturing, this checkbox is set by
default. See https://wiki.wireshark.org/Development/PcapNg
for more details on pcap-ng.
Next file every n megabyte(s) Multiple files only. Switch to the next file after the given
number of byte(s)/kilobyte(s)/megabyte(s)/gigabyte(s) have
been captured.
Next file every n minute(s) Multiple files only: Switch to the next file after the given
number of second(s)/minutes(s)/hours(s)/days(s) have elapsed.
Ring buffer with n files Multiple files only: Form a ring buffer of the capture files with
the given number of files.
Stop capture after n file(s) Multiple files only: Stop capturing after switching to the next
file the given number of times.
4.5.3. Stop Capture… frame
… after n packet(s) Stop capturing after the given number of packets have been
captured.
… after n megabytes(s) Stop capturing after the given number of byte(s)/kilobyte(s)/
megabyte(s)/gigabyte(s) have been captured. This option is
greyed out if “Use multiple files” is selected.
… after n minute(s) Stop capturing after the given number of second(s)/minutes(s)/
hours(s)/days(s) have elapsed.
4.5.4. Display Options frame
Update list of packets in real time This option allows you to specify that Wireshark should update
the packet list pane in real time. If you do not specify this,
Page view 73
1 2 ... 69 70 71 72 73 74 75 76 77 78 79 ... 227 228

Comments to this Manuals

No comments