Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout

Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout

10.03.2013 Views

Capture Mode Adaptive Capture (Default) Raw Capture EARLY FIELD TRIAL Chapter 5 Summary Postcapture Analysis In Adaptive Capture mode, Sniffer Adaptive Application Analyzer extracts key fields from supported protocols and generates Adaptive Session Packets (ASPs) with derived payloads and compressed packet headers through the transport (TCP/UDP) layer. Hexadecimal bytes are not displayed for ASPs. In addition, Sniffer Adaptive Application Analyzer stores metadata correlating ASPs with parent sessions to provide a flow-aware view of network data. You can drill between the session view and the decode view during postcapture analysis to get both the top-down and bottom-up perspective. In Raw Capture mode, Sniffer Adaptive Application Analyzer records packets as seen on the wire, including payloads (an optional packet slice setting can be used). In addition session statistics are not available. Instead, traditional tri-paned packet decodes, Expert analysis, and post-analysis tabs are available. Set a Capture Buffer Size 112 Sniffer Adaptive Application Analyzer Use the Capture Buffer Size field to specify the size of the Sniffer Adaptive Application Analyzer capture buffer. You can enter values from 200 MB - 1 GB. Capture stops automatically when the buffer fills. Set the Packet Slice Size Separate, correlated views provide session and packet statistics: • Adaptive Session View provides access to adaptive session records (ASRs). • Adaptive Decode View provides line by line interpretation of adaptive session packets (ASPs). •Tri-pane packet decodes • Expert analyzer • Post-analysis tabs (Host Table, Matrix, Protocol Distribution, Statistics) The Configure Capture dialog box provides a different slicing option depending on the selected capture mode. The table below summarizes how to configure packet slicing for both Adaptive and Raw mode.

EARLY FIELD TRIAL Capture Mode Adaptive Capture (Default) Raw Capture Available Packet Slice Option Adaptive Packet Slice Size Raw Packet Slice Size Start Capture! Description Capturing and Mining Data When Adaptive capture is enabled, Sniffer Adaptive Application Analyzer generates Adaptive Session Packets for all protocols with an ASI Protocol Interpreter. You use the Adaptive Packet Slice Size option to specify how much of each packet without an ASI protocol interpreter Sniffer Adaptive Application Analyzer should capture. There are two classes of packets without an ASI Protocol Interpreter: • Standard IPv4 Protocols on Well-Known TCP/UDP Ports Sniffer Adaptive Application Analyzer still records generic session metadata for these protocols, either listing them using hardcoded aliases or identifying them as GENERIC (refer to Session View for GENERIC Protocols on page 150 for details. • Others (Non-IPv4) Sniffer Adaptive Application Analyzer does not record any session metadata for these packets. Refer to Protocols Supported for Sniffer Adaptive Processing on page 18 for a list of protocols with ASI protocol interpreters. When Raw capture is enabled, you use the Raw Packet Slice Size option to specify how much of each packet to capture. Once you have finished configuring the capture session, start capture with either the Start Capture button in the toolbar or the Quick Select > Start Capture menu item. Once you start capturing packets, the Availability Meter at the base of the Graph panel changes from Yellow to Green (Figure 5-3), indicating that both packet data (adaptive or raw) and monitoring statistics are available. You can view statistics in the Statistics panel, as well as mine this portion of the stream for packets. Refer to Availability Meter on page 56 for details. User’s Guide 113

Capture<br />

<strong>Mode</strong><br />

<strong>Adaptive</strong><br />

Capture<br />

(Default)<br />

Raw<br />

Capture<br />

EARLY FIELD TRIAL Chapter 5<br />

Summary Postcapture Analysis<br />

In <strong>Adaptive</strong> Capture mode, <strong>Sniffer</strong> <strong>Adaptive</strong><br />

<strong>Application</strong> <strong>Analyzer</strong> extracts key fields from<br />

supported protocols and generates <strong>Adaptive</strong> Session<br />

Packets (ASPs) with derived payloads and<br />

compressed packet headers through the transport<br />

(TCP/UDP) layer. Hexadecimal bytes are not<br />

displayed for ASPs.<br />

In addition, <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong><br />

stores metadata correlating ASPs with parent<br />

sessions to provide a flow-aware view of network<br />

data. You can drill between the session view and the<br />

decode view during postcapture analysis to get both<br />

the top-down and bottom-up perspective.<br />

In Raw Capture mode, <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong><br />

<strong>Analyzer</strong> records packets as seen on the wire,<br />

including payloads (an optional packet slice setting<br />

can be used). In addition session statistics are not<br />

available. Instead, traditional tri-paned packet<br />

decodes, Expert analysis, and post-analysis tabs are<br />

available.<br />

Set a Capture Buffer Size<br />

112 <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong><br />

Use the Capture Buffer Size field to specify the size of the <strong>Sniffer</strong><br />

<strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong> capture buffer. You can enter values from<br />

200 MB - 1 GB. Capture stops automatically when the buffer fills.<br />

Set the Packet Slice Size<br />

Separate, correlated views<br />

provide session and packet<br />

statistics:<br />

• <strong>Adaptive</strong> Session View<br />

provides access to<br />

adaptive session<br />

records (ASRs).<br />

• <strong>Adaptive</strong> Decode View<br />

provides line by line<br />

interpretation of<br />

adaptive session<br />

packets (ASPs).<br />

•Tri-pane packet<br />

decodes<br />

• Expert analyzer<br />

• Post-analysis tabs<br />

(Host Table, Matrix,<br />

Protocol Distribution,<br />

Statistics)<br />

The Configure Capture dialog box provides a different slicing option<br />

depending on the selected capture mode. The table below summarizes<br />

how to configure packet slicing for both <strong>Adaptive</strong> and Raw mode.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!