This is a question fairly deep in the guts of Wireshark that I could not find an answer to.
When a capture filter is implemented are ALL packets sent to Wireshark/Dumpcap/TShark at the software level for filtering or are the packets not matching the filter shedded/ignored by the Network Interface card itself thus reducing strain on the CPU/Network Fabric? I look forward to hearing from you!
___________________________________________________________________________ Sent via: Wireshark-dev mailing list <wireshark-dev@wireshark.org> Archives: https://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe