• Home
  • My Tools
  • Visio Stencils
  • Online Tools
  • PS Scripts
  • PS One Liners
  • Downloads
  • Product Review
  • About

Smarter Together

~ by I.M.H.O.

Smarter Together

Category Archives: Wireshark

Wireshark Trace file too large to open

20 Tuesday Dec 2011

Posted by Paul Bloem in Quick Reference Guide, Troubleshooting, Wireshark

≈ Leave a comment

While looking for an evasive SIP Gateway related problem I used wireshark to collect additional traffic. Unfortunatly once I had taken the wirshark capture file (which had grown to almost 2 GB) to my laptop for analyzing I found that it lacked sufficient memory to load this enormous capture file.
I found that wirshark shipped with tools that have the ability to split the capture to a manageable size. How does it work?

You can split the capture file as follows:-

1. From CMD Navigate to c:\Progran Files\Wireshark
 
2. Run the command: capinfos -c c:\xxxxx.pcap – Where xxxxx.pcap is your capture file
 
3.  This will give you the number of packets in the trace so can decide how to split the file. Only 290 packets in my screenshot 🙂
 
 
4. Run the command: editcap -c 400000 c:\xxxxx.pcap c:\splittrace.pcap – Where 400000 is the number of packets in each output split segment, and the source and destination files are mentioned next
5. You will now have as many files as required to complete the split, they will be called what you stated as the dest file above followed by -0000, -0001 etc
Search Description
Advertisement

Share this:

  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • Click to share on LinkedIn (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Pocket (Opens in new window)
  • Click to share on Pinterest (Opens in new window)
  • Click to share on Tumblr (Opens in new window)
  • Click to share on Skype (Opens in new window)
  • Click to email a link to a friend (Opens in new window)
  • Click to print (Opens in new window)

Like this:

Like Loading...

IMHO YouTube Channel

Follow Smarter Together on WordPress.com

Enter your email address to subscribe and receive notifications of new posts.

Join 674 other subscribers

Show your appreciation by donating

Archives

Category

ABS ABServer ADContacts Address Book AddressBook AddressBook Service Communicator contacts CX500 Devices DHCP DNS Edge Server Error Codes event id Exchange UM 2010 GAL Install Guide Lync 2013 Tools Lync Edge Lync Tools Microsoft Teams Monitoring Polycom Powershell Scripts Product Review QOS Quick Reference Guide Reskit RGS RTC Database SIP SIP Options Skype for Business Skype for Business Monitoring Skype for Business Tools SQL Teams TMG Tool Tools Troubleshoot Edge UC Sorted Tools UM Uncategorized Unified Messaging visio Visio Stencil voicemail

Create a free website or blog at WordPress.com.

Privacy & Cookies: This site uses cookies. By continuing to use this website, you agree to their use.
To find out more, including how to control cookies, see here: Cookie Policy
  • Follow Following
    • Smarter Together
    • Join 63 other followers
    • Already have a WordPress.com account? Log in now.
    • Smarter Together
    • Customize
    • Follow Following
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar
%d bloggers like this: