File parsing on Pcap file There's a lot of information on the web, and I don't know it here.
Experience One: Wireshark Runtime Error
In general, Wireshark is not suitable for long-time capture packages, that is, over time, will always report the above errors, generally as follows:
Because Wireshark data is kept in memory, so as the capture time increases, it will be reported memory overflow error, it seems that the memory is not freed ... This is a bug in Wireshark.
Experience Two: Multi-file capture
With this in mind, it's easy to think of saving the captured data into multiple files, so you'll use the following settings:
Refer to the blog http://www.cnblogs.com/caoguoping100/p/3658792.html for specific actions
In addition to the last command I think the wrong thing to say, the other blog is very clear about the story.
However, it did not solve the problem because ... Wireshark still does not release memory.
Interested can be read carefully under: https://wiki.wireshark.org/KnownBugs/OutOfMemory
Experience Three: the use of windump
Since the above are not feasible, then use tcpdump this good tool, but because the server is Windows, so you can only choose to have windows under the tcpdump of the windump, however, I found lost packets ... and particularly serious. Well, you ask me how I know that in
, there is a capture length, which is significantly smaller than the length of the package.
I don't know why .... So you don't have to use this tool.
Experience Four: dumpcap command use
Solve the problem is seen from this, https://blog.packet-foo.com/2013/05/the-notorious-wireshark-out-of-memory-problem/, Of course, the link to the blog Park mentioned earlier is also written.
Wireshark actually call is the Dumpcap command, and this default in the Wireshark installation time exists, so very convenient, specific use can
dumpcap -h #帮助命令
It is worth mentioning that the default Dumpcap default save is the pcapng format, unlike the PCAP format, if you want to save the file is Pcap format, you need to specify the-p parameter.
Above, the last one dumpcap solve the problem.
Wireshark Usage Experience