Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout
Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout
Searching Adaptive Views EARLY FIELD TRIAL Chapter 7 158 Sniffer Adaptive Application Analyzer Because the postcapture display can include thousands and thousands of entries, it can be useful to search for particular frames. Using Sniffer Adaptive Application Analyzer’s powerful search abilities, you can search for frames in the Adaptive Session and Decode views that match a text string in either the Summary or Detail views. NOTE: In addition to searching for frames, you can also advance to a particular frame in the Decode tab by specifying its number. Do this by selecting the Go to Frame command from the Display menu and supplying the frame number in the dialog box that appears. To search for packets matching a text string: 1 Display the Find Frame dialog box using any of the following commands: Select Find Frame from the Display menu. Select Find Frame from the Decode tab’s context menu (activated by right-clicking anywhere on the Decode tab). Use the Alt-F3 keyboard shortcut. The Find Frame dialog box contains only a Text tab when launched from an Adaptive view. The Text tab lets you search for frames containing a specified text string. 2 Enter the text to search in the field provided. The dropdown list includes previously performed text searches. 3 Specify in which portion of the Decode tab to search for the specified from the options provided. 4 Specify whether the search is case-sensitive using the Match case option. 5 Specify the search direction. 6 Click OK. If the string is found, the entry containing the text will be displayed in the postcapture. Press F3 to search for the next packet matching the same criteria.
EARLY FIELD TRIAL Using Filters with Adaptive Postcapture Views Adaptive Session Analysis You can use filters created from the Quick Select window independently against both the Adaptive Session and Adaptive Decode views. Use the the Create/Apply Filter command, either from the Display menu or from the right-click context menu. Keep in mind that display filters used with Adaptive views are limited to IP Address and Port criteria. Refer to Applying Adaptive Display Filters on page 136 for details on using filters with Adaptive views. Enabling VLAN Data Collection If Sniffer Adaptive Application Analyzer is connected to a switch SPAN port, make sure you enable VLAN data collection on the network interface card to prevent VLAN IDs from being stripped before the application sees them. With VLAN data collection enabled, you’ll be able to see VLAN IDs in postcapture decodes. Refer to the Sniffer Adaptive Application Analyzer Installation Guide for details on usin g the sniffer_vlan_edit.exe tool included with the product to enable VLAN data collection for adapters using Intel and Broadcom chipsets. User’s Guide 159
- Page 107 and 108: EARLY FIELD TRIAL SECTION 2 Capturi
- Page 109 and 110: EARLY FIELD TRIAL Capturing and Min
- Page 111 and 112: EARLY FIELD TRIAL Configuring and S
- Page 113 and 114: EARLY FIELD TRIAL Capture Mode Adap
- Page 115 and 116: EARLY FIELD TRIAL Mining Packet Dat
- Page 117 and 118: EARLY FIELD TRIAL Capturing and Min
- Page 119 and 120: EARLY FIELD TRIAL Using Filters in
- Page 121 and 122: EARLY FIELD TRIAL Reusable Filters
- Page 123 and 124: EARLY FIELD TRIAL Figure 6-2. Apply
- Page 125 and 126: EARLY FIELD TRIAL Working with Auto
- Page 127 and 128: EARLY FIELD TRIAL Table 6-3. Filter
- Page 129 and 130: EARLY FIELD TRIAL Using Filters in
- Page 131 and 132: EARLY FIELD TRIAL Using Pattern Mat
- Page 133 and 134: EARLY FIELD TRIAL Applying Mining F
- Page 135 and 136: EARLY FIELD TRIAL Using Filters in
- Page 137 and 138: EARLY FIELD TRIAL Adaptive Display
- Page 139 and 140: EARLY FIELD TRIAL SECTION 3 Analyzi
- Page 141 and 142: EARLY FIELD TRIAL Adaptive Session
- Page 143 and 144: EARLY FIELD TRIAL Adaptive Mode Pos
- Page 145 and 146: EARLY FIELD TRIAL Adaptive Session
- Page 147 and 148: EARLY FIELD TRIAL Adaptive Session
- Page 149 and 150: EARLY FIELD TRIAL Session Overview
- Page 151 and 152: EARLY FIELD TRIAL Drilling Down to
- Page 153 and 154: EARLY FIELD TRIAL Adaptive Decode V
- Page 155 and 156: EARLY FIELD TRIAL Opening ASP Files
- Page 157: EARLY FIELD TRIAL Figure 7-9. Openi
- Page 161 and 162: EARLY FIELD TRIAL Raw Capture Mode
- Page 163 and 164: EARLY FIELD TRIAL Table 8-1. Postca
- Page 165 and 166: EARLY FIELD TRIAL Introducing the P
- Page 167 and 168: EARLY FIELD TRIAL Granularity in De
- Page 169 and 170: EARLY FIELD TRIAL Packet Status Fla
- Page 171 and 172: EARLY FIELD TRIAL Table 8-5. Decode
- Page 173 and 174: EARLY FIELD TRIAL Types of Display
- Page 175 and 176: EARLY FIELD TRIAL Raw Capture Mode
- Page 177 and 178: EARLY FIELD TRIAL a The “Apply on
- Page 179 and 180: EARLY FIELD TRIAL Raw Capture Mode
- Page 181 and 182: EARLY FIELD TRIAL Raw Capture Mode
- Page 183 and 184: EARLY FIELD TRIAL Raw Capture Mode
- Page 185 and 186: EARLY FIELD TRIAL Using the Manual
- Page 187 and 188: EARLY FIELD TRIAL 5 Click OK. Figur
- Page 189 and 190: EARLY FIELD TRIAL Raw Capture Mode
- Page 191 and 192: EARLY FIELD TRIAL Setting Display S
- Page 193 and 194: EARLY FIELD TRIAL Raw Capture Mode
- Page 195 and 196: EARLY FIELD TRIAL Table 8-9. Summar
- Page 197 and 198: EARLY FIELD TRIAL Raw Capture Mode
- Page 199 and 200: EARLY FIELD TRIAL Searching for Fra
- Page 201 and 202: EARLY FIELD TRIAL Raw Capture Mode
- Page 203 and 204: EARLY FIELD TRIAL Raw Capture Mode
- Page 205 and 206: EARLY FIELD TRIAL Raw Capture Mode
- Page 207 and 208: EARLY FIELD TRIAL Printing Decoded
EARLY FIELD TRIAL<br />
Using Filters with <strong>Adaptive</strong> Postcapture Views<br />
<strong>Adaptive</strong> Session Analysis<br />
You can use filters created from the Quick Select window independently<br />
against both the <strong>Adaptive</strong> Session and <strong>Adaptive</strong> Decode views. Use the<br />
the Create/Apply Filter command, either from the Display menu or<br />
from the right-click context menu. Keep in mind that display filters used<br />
with <strong>Adaptive</strong> views are limited to IP Address and Port criteria.<br />
Refer to Applying <strong>Adaptive</strong> Display Filters on page 136 for details on<br />
using filters with <strong>Adaptive</strong> views.<br />
Enabling VLAN Data Collection<br />
If <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong> is connected to a switch SPAN<br />
port, make sure you enable VLAN data collection on the network<br />
interface card to prevent VLAN IDs from being stripped before the<br />
application sees them. With VLAN data collection enabled, you’ll be able<br />
to see VLAN IDs in postcapture decodes.<br />
Refer to the <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong> Installation Guide for<br />
details on usin g the sniffer_vlan_edit.exe tool included with the<br />
product to enable VLAN data collection for adapters using Intel and<br />
Broadcom chipsets.<br />
User’s Guide 159