Why you can't parallelize tshark, and what I did insteadhttps://www.reddit.com/r/programming/comments/1vytn44/why_you_cant_parallelize_tshark_and_what_i_did
Follow-up to my post a couple of weeks ago about a 2.5 GB PCAP that took 6-7 hours to process. Streaming tshark's output into Go got it to 70 minutes, but it was still single-threaded. The most common response here was: why not just add goroutines? Turns out you can't, and the reason is that tshark's dissection is linear state. What it reads in one packet determines how it decodes the next β TCP reassembly, connection tracking, anything under tcp.analysis.* reads and updates shared conversation tables as it goes. Strict ordering isn't a design choice, it's what dissection requires. Goroutinβ¦