Continuous Packet Capture


#1

Hi,

What is the best way for continuous packet capture from a tap/span port? Let’s say i have 10 TB’s of space, and i wan’t to capture data, and start overwriting the oldest data when disk is full.
Is Wireshark the best way to do this, or is there any other way to get the job done.

The analyzing of the data is not important, as long as i get .PCAP and can import it into an analyzer tool.

Thank you.


#2

Also, if using wireshark and splitting the files etc. Can wireshark also start overwriting when disk is full?