There is always the "Add to reputation" under my name if you want to give more thanks

Reputation is always appreciated
With wireshark there are a few more options to decrease CPU. Go to capture -- options and put in the tcp.port filter there (you can also add a capture filter for ip.addr != 192.168.0.1 and use YOUR ip address, this will stop your traffic from eating up CPU). The display filter only filters what is showed on the screen but the capture filter stops it from logging, writing to disk, displaying on grid, deep packet analysis, etc.
In the same screen set it to log to a file and under Display Options disable "Update list of packets in real time", "Autmatic scrolling in live capture". Under "Name Resolution" deselect all 3 checkboxes. This should significant decrease the Wireshark overhead. Let me know how that works for you
Out of curiosity -- what sites are you trying to bust your roomies visiting?
Last edited by sknake; Aug 2nd, 2009 at 3:06 pm.
Reputation Points: 1749
Solved Threads: 735
Senior Poster
Offline 3,948 posts
since Feb 2009