J. R. DePriest :verified_trans: :donor: :Moopsy: :EA DATA. SF:<p>During a recent change management call, one of the app teams was talking about running Wireshark on their four app servers to capture an elusive authentication timeout event. They would have to filter for all traffic coming and going to all 16 of our domain controllers and were expecting to run it for up to 24 hours.<br>The networking team lead immediately spoke up and told them that would probably fill their hard drives and use all their RAM and they should probably rethink it.<br>The app team admitted they had no experience with Wireshark and were just following the advice of their vendor's tech support.<br>I asked them why they didn't just use <code>tshark</code> or <code>dumpcap</code> which is how I got roped into helping them with their change.<br>I was able to step in and help them use <code>dumpcap</code> instead of Wireshark. I built them a command that would create 50 MB pcap files and stop when it hit a total file count that was the equivalent to half of the available disk space (each server had the same amount of free space on the secondary drive).<br>I was proud of myself for being able to leverage the shit I've learned OTJ and via my SANS GIAC certifications.<br>It was a little thing, but it saved them a lot of trouble and possibly crashing their servers.<br>It's nice when teams can work together.</p><p><a href="https://infosec.exchange/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://infosec.exchange/tags/Wireshark" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Wireshark</span></a> <a href="https://infosec.exchange/tags/tshark" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tshark</span></a> <a href="https://infosec.exchange/tags/dumpcap" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dumpcap</span></a> <a href="https://infosec.exchange/tags/SANS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SANS</span></a> <a href="https://infosec.exchange/tags/GIAC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GIAC</span></a></p>