Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout
Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout
Capture Mode Adaptive Capture (Default) Raw Capture EARLY FIELD TRIAL Chapter 5 Summary Postcapture Analysis In Adaptive Capture mode, Sniffer Adaptive Application Analyzer extracts key fields from supported protocols and generates Adaptive Session Packets (ASPs) with derived payloads and compressed packet headers through the transport (TCP/UDP) layer. Hexadecimal bytes are not displayed for ASPs. In addition, Sniffer Adaptive Application Analyzer stores metadata correlating ASPs with parent sessions to provide a flow-aware view of network data. You can drill between the session view and the decode view during postcapture analysis to get both the top-down and bottom-up perspective. In Raw Capture mode, Sniffer Adaptive Application Analyzer records packets as seen on the wire, including payloads (an optional packet slice setting can be used). In addition session statistics are not available. Instead, traditional tri-paned packet decodes, Expert analysis, and post-analysis tabs are available. Set a Capture Buffer Size 112 Sniffer Adaptive Application Analyzer Use the Capture Buffer Size field to specify the size of the Sniffer Adaptive Application Analyzer capture buffer. You can enter values from 200 MB - 1 GB. Capture stops automatically when the buffer fills. Set the Packet Slice Size Separate, correlated views provide session and packet statistics: • Adaptive Session View provides access to adaptive session records (ASRs). • Adaptive Decode View provides line by line interpretation of adaptive session packets (ASPs). •Tri-pane packet decodes • Expert analyzer • Post-analysis tabs (Host Table, Matrix, Protocol Distribution, Statistics) The Configure Capture dialog box provides a different slicing option depending on the selected capture mode. The table below summarizes how to configure packet slicing for both Adaptive and Raw mode.
EARLY FIELD TRIAL Capture Mode Adaptive Capture (Default) Raw Capture Available Packet Slice Option Adaptive Packet Slice Size Raw Packet Slice Size Start Capture! Description Capturing and Mining Data When Adaptive capture is enabled, Sniffer Adaptive Application Analyzer generates Adaptive Session Packets for all protocols with an ASI Protocol Interpreter. You use the Adaptive Packet Slice Size option to specify how much of each packet without an ASI protocol interpreter Sniffer Adaptive Application Analyzer should capture. There are two classes of packets without an ASI Protocol Interpreter: • Standard IPv4 Protocols on Well-Known TCP/UDP Ports Sniffer Adaptive Application Analyzer still records generic session metadata for these protocols, either listing them using hardcoded aliases or identifying them as GENERIC (refer to Session View for GENERIC Protocols on page 150 for details. • Others (Non-IPv4) Sniffer Adaptive Application Analyzer does not record any session metadata for these packets. Refer to Protocols Supported for Sniffer Adaptive Processing on page 18 for a list of protocols with ASI protocol interpreters. When Raw capture is enabled, you use the Raw Packet Slice Size option to specify how much of each packet to capture. Once you have finished configuring the capture session, start capture with either the Start Capture button in the toolbar or the Quick Select > Start Capture menu item. Once you start capturing packets, the Availability Meter at the base of the Graph panel changes from Yellow to Green (Figure 5-3), indicating that both packet data (adaptive or raw) and monitoring statistics are available. You can view statistics in the Statistics panel, as well as mine this portion of the stream for packets. Refer to Availability Meter on page 56 for details. User’s Guide 113
- Page 61 and 62: EARLY FIELD TRIAL Pie Chart Working
- Page 63 and 64: EARLY FIELD TRIAL Column Chart Work
- Page 65 and 66: EARLY FIELD TRIAL Time Series Chart
- Page 67 and 68: EARLY FIELD TRIAL Working with the
- Page 69 and 70: EARLY FIELD TRIAL Working with the
- Page 71 and 72: EARLY FIELD TRIAL Using the Statist
- Page 73 and 74: EARLY FIELD TRIAL Summary Tab a Usi
- Page 75 and 76: EARLY FIELD TRIAL Using the Statist
- Page 77 and 78: EARLY FIELD TRIAL Port Tab Using th
- Page 79 and 80: EARLY FIELD TRIAL Network Tab Using
- Page 81 and 82: EARLY FIELD TRIAL Destination Tab U
- Page 83 and 84: EARLY FIELD TRIAL Using the Statist
- Page 85 and 86: EARLY FIELD TRIAL VLAN ID Tab Using
- Page 87 and 88: EARLY FIELD TRIAL Reports Tabs Usi
- Page 89 and 90: EARLY FIELD TRIAL Top Conversations
- Page 91 and 92: EARLY FIELD TRIAL Multicast Protoco
- Page 93 and 94: EARLY FIELD TRIAL Working with the
- Page 95 and 96: EARLY FIELD TRIAL Using the Statist
- Page 97 and 98: EARLY FIELD TRIAL Refreshing Statis
- Page 99 and 100: EARLY FIELD TRIAL Using the Statist
- Page 101 and 102: EARLY FIELD TRIAL Showing and Hidin
- Page 103 and 104: EARLY FIELD TRIAL Resolving DNS Nam
- Page 105 and 106: EARLY FIELD TRIAL Table 4-1. New Co
- Page 107 and 108: EARLY FIELD TRIAL SECTION 2 Capturi
- Page 109 and 110: EARLY FIELD TRIAL Capturing and Min
- Page 111: EARLY FIELD TRIAL Configuring and S
- Page 115 and 116: EARLY FIELD TRIAL Mining Packet Dat
- Page 117 and 118: EARLY FIELD TRIAL Capturing and Min
- Page 119 and 120: EARLY FIELD TRIAL Using Filters in
- Page 121 and 122: EARLY FIELD TRIAL Reusable Filters
- Page 123 and 124: EARLY FIELD TRIAL Figure 6-2. Apply
- Page 125 and 126: EARLY FIELD TRIAL Working with Auto
- Page 127 and 128: EARLY FIELD TRIAL Table 6-3. Filter
- Page 129 and 130: EARLY FIELD TRIAL Using Filters in
- Page 131 and 132: EARLY FIELD TRIAL Using Pattern Mat
- Page 133 and 134: EARLY FIELD TRIAL Applying Mining F
- Page 135 and 136: EARLY FIELD TRIAL Using Filters in
- Page 137 and 138: EARLY FIELD TRIAL Adaptive Display
- Page 139 and 140: EARLY FIELD TRIAL SECTION 3 Analyzi
- Page 141 and 142: EARLY FIELD TRIAL Adaptive Session
- Page 143 and 144: EARLY FIELD TRIAL Adaptive Mode Pos
- Page 145 and 146: EARLY FIELD TRIAL Adaptive Session
- Page 147 and 148: EARLY FIELD TRIAL Adaptive Session
- Page 149 and 150: EARLY FIELD TRIAL Session Overview
- Page 151 and 152: EARLY FIELD TRIAL Drilling Down to
- Page 153 and 154: EARLY FIELD TRIAL Adaptive Decode V
- Page 155 and 156: EARLY FIELD TRIAL Opening ASP Files
- Page 157 and 158: EARLY FIELD TRIAL Figure 7-9. Openi
- Page 159 and 160: EARLY FIELD TRIAL Using Filters wit
- Page 161 and 162: EARLY FIELD TRIAL Raw Capture Mode
Capture<br />
<strong>Mode</strong><br />
<strong>Adaptive</strong><br />
Capture<br />
(Default)<br />
Raw<br />
Capture<br />
EARLY FIELD TRIAL Chapter 5<br />
Summary Postcapture Analysis<br />
In <strong>Adaptive</strong> Capture mode, <strong>Sniffer</strong> <strong>Adaptive</strong><br />
<strong>Application</strong> <strong>Analyzer</strong> extracts key fields from<br />
supported protocols and generates <strong>Adaptive</strong> Session<br />
Packets (ASPs) with derived payloads and<br />
compressed packet headers through the transport<br />
(TCP/UDP) layer. Hexadecimal bytes are not<br />
displayed for ASPs.<br />
In addition, <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong><br />
stores metadata correlating ASPs with parent<br />
sessions to provide a flow-aware view of network<br />
data. You can drill between the session view and the<br />
decode view during postcapture analysis to get both<br />
the top-down and bottom-up perspective.<br />
In Raw Capture mode, <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong><br />
<strong>Analyzer</strong> records packets as seen on the wire,<br />
including payloads (an optional packet slice setting<br />
can be used). In addition session statistics are not<br />
available. Instead, traditional tri-paned packet<br />
decodes, Expert analysis, and post-analysis tabs are<br />
available.<br />
Set a Capture Buffer Size<br />
112 <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong><br />
Use the Capture Buffer Size field to specify the size of the <strong>Sniffer</strong><br />
<strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong> capture buffer. You can enter values from<br />
200 MB - 1 GB. Capture stops automatically when the buffer fills.<br />
Set the Packet Slice Size<br />
Separate, correlated views<br />
provide session and packet<br />
statistics:<br />
• <strong>Adaptive</strong> Session View<br />
provides access to<br />
adaptive session<br />
records (ASRs).<br />
• <strong>Adaptive</strong> Decode View<br />
provides line by line<br />
interpretation of<br />
adaptive session<br />
packets (ASPs).<br />
•Tri-pane packet<br />
decodes<br />
• Expert analyzer<br />
• Post-analysis tabs<br />
(Host Table, Matrix,<br />
Protocol Distribution,<br />
Statistics)<br />
The Configure Capture dialog box provides a different slicing option<br />
depending on the selected capture mode. The table below summarizes<br />
how to configure packet slicing for both <strong>Adaptive</strong> and Raw mode.