10.03.2013 Views

Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout

Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout

Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

About <strong>Sniffer</strong> <strong>Adaptive</strong> Intelligence<br />

EARLY FIELD TRIAL Chapter 1<br />

16 <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong><br />

<strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong> introduces new <strong>Adaptive</strong> Session<br />

Intelligence technology that streamlines packet-level analysis for<br />

critical protocols while augmenting it with session-awareness. The<br />

<strong>Adaptive</strong> capture mode stores both <strong>Adaptive</strong> Session Packets (ASPs) for<br />

bit-level analysis and correlated <strong>Adaptive</strong> Session Records (ASRs) for<br />

session analysis:<br />

<strong>Adaptive</strong> Session Intelligence extracts and preserves key fields<br />

from supported packet types, storing condensed <strong>Adaptive</strong><br />

Session Packets (ASPs) rather than raw packets for supported<br />

protocols.<br />

ASPs include compressed packet headers through the transport<br />

layer and an intelligently “derived” payload rather than the actual<br />

payload. ASPs are much smaller than their raw counterparts and<br />

can be stored and analyzed much more efficiently. They are also<br />

correlated with parent <strong>Adaptive</strong> Session Records for session<br />

analysis.<br />

The exact fields preserved in an ASP vary by protocol but include<br />

compressed MAC/IP headers and key data fields (for example, SQL<br />

calls embedded in the data portion of an HTTP packet).<br />

<strong>Adaptive</strong> Session Records (ASRs) store metadata for flow<br />

analysis, providing end-to-end transaction metrics, including:<br />

Source/Destination Identifiers<br />

Session start/end times<br />

Latency metrics, success/failure codes, and error messages.<br />

<strong>Application</strong>-specific metrics for HTTP, DNS, Media (RTP), Mail<br />

(SMTP/POP), FTP, and so on.<br />

You work with ASRs and ASPs in separate Session and Decode views<br />

(Figure 1-3). The <strong>Adaptive</strong> Session and Decode views are very similar to<br />

the classic <strong>Sniffer</strong> decode window, allowing you to perform network<br />

analysis in Summary and Detail panes. Correlation between a session<br />

and its underlying ASPs let you drill back and forth between the two<br />

views. You get both the top down view of a complete session and the<br />

constituent packet level details.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!