Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout
Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout
Working with Display Filters EARLY FIELD TRIAL Chapter 8 172 Sniffer Adaptive Application Analyzer A filter applied to the display of captured data is called a display filter. Display filters let you select the packets you want to display in a Decode tab. Display filters do not affect the contents of the capture buffer. They just prevent some of the data from being displayed. You can use display filters to view only: Packets transmitted between network nodes (or address pairs) Packets that belong to one or more protocol groups Packets that match predefined data patterns Error packets Packets that belong to a certain size range Packets that match various combinations of the above specifications
EARLY FIELD TRIAL Types of Display Filters Raw Capture Mode Postcapture Analysis Sniffer Adaptive Application Analyzer provides several types of display filters: NOTE: Display filters are separate from Quick Select window filters. Refer to Using Filters in the Quick Select Window on page 119 for information on how to create Quick Select window filters and apply them as source, mining, and statistics filters. Table 8-6. Sniffer Adaptive Application Analyzer Display Filters Filter Type Description Automatic Display Filters Using Automatic Display Filters on page 174 Quick Display Filters Using Quick Filters on page 178 Manual Display Filters (Display > Define Filter) Using Manual Filters (Display > Define Filter) on page 183 Expert Display Filters Setting Automatic Expert Display Filters on page 222 You can automatically populate the Define Filter - Display dialog box’s tabs with filter settings based on selected portions of the currently selected packet in the Decode tab. You do this by using the dropdown at the top of the Decode tab to specify which portion of the selected packet you want to use as a filter (for example, just the source IP address) and clicking the Define Display Filter button. Quick Display Filters are similar to automatic display filters – they filter the active Decode tab based on selected portions of the currently selected packet in the Decode tab. The main difference is that they take effect immediately without displaying the Define Filter dialog box first. You set Quick Filters by using the dropdown at the top of the Decode tab to specify which portion of the selected packet you want to use as a filter (for example, just the source port) and clicking the Quick Filter button. Note: You set global options for how Quick Filters are applied in the Display > Display Setup > Packet Selection tab. These options specify to which packets Quick Filters should be applied (all or selected) and how results should be returned (by selecting/clearing packets in the active tab or by showing a new filtered tab at the base of the postcapture display window). You can set Display filters manually in the Define Filter - Display dialog box. This dialog box is available by using the Display > Define Filter command. Then, you have full access to the standard Define Filter tabs described in Using Manual Filters (Display > Define Filter) on page 183. You can also set automatic Expert filters that only display data associated with a particular network object, symptom, or diagnosis. You do this by displaying the Expert tab, selecting an object, symptom, or diagnosis and clicking the Display Filter button. User’s Guide 173
- Page 121 and 122: EARLY FIELD TRIAL Reusable Filters
- Page 123 and 124: EARLY FIELD TRIAL Figure 6-2. Apply
- Page 125 and 126: EARLY FIELD TRIAL Working with Auto
- Page 127 and 128: EARLY FIELD TRIAL Table 6-3. Filter
- Page 129 and 130: EARLY FIELD TRIAL Using Filters in
- Page 131 and 132: EARLY FIELD TRIAL Using Pattern Mat
- Page 133 and 134: EARLY FIELD TRIAL Applying Mining F
- Page 135 and 136: EARLY FIELD TRIAL Using Filters in
- Page 137 and 138: EARLY FIELD TRIAL Adaptive Display
- Page 139 and 140: EARLY FIELD TRIAL SECTION 3 Analyzi
- Page 141 and 142: EARLY FIELD TRIAL Adaptive Session
- Page 143 and 144: EARLY FIELD TRIAL Adaptive Mode Pos
- Page 145 and 146: EARLY FIELD TRIAL Adaptive Session
- Page 147 and 148: EARLY FIELD TRIAL Adaptive Session
- Page 149 and 150: EARLY FIELD TRIAL Session Overview
- Page 151 and 152: EARLY FIELD TRIAL Drilling Down to
- Page 153 and 154: EARLY FIELD TRIAL Adaptive Decode V
- Page 155 and 156: EARLY FIELD TRIAL Opening ASP Files
- Page 157 and 158: EARLY FIELD TRIAL Figure 7-9. Openi
- Page 159 and 160: EARLY FIELD TRIAL Using Filters wit
- Page 161 and 162: EARLY FIELD TRIAL Raw Capture Mode
- Page 163 and 164: EARLY FIELD TRIAL Table 8-1. Postca
- Page 165 and 166: EARLY FIELD TRIAL Introducing the P
- Page 167 and 168: EARLY FIELD TRIAL Granularity in De
- Page 169 and 170: EARLY FIELD TRIAL Packet Status Fla
- Page 171: EARLY FIELD TRIAL Table 8-5. Decode
- Page 175 and 176: EARLY FIELD TRIAL Raw Capture Mode
- Page 177 and 178: EARLY FIELD TRIAL a The “Apply on
- Page 179 and 180: EARLY FIELD TRIAL Raw Capture Mode
- Page 181 and 182: EARLY FIELD TRIAL Raw Capture Mode
- Page 183 and 184: EARLY FIELD TRIAL Raw Capture Mode
- Page 185 and 186: EARLY FIELD TRIAL Using the Manual
- Page 187 and 188: EARLY FIELD TRIAL 5 Click OK. Figur
- Page 189 and 190: EARLY FIELD TRIAL Raw Capture Mode
- Page 191 and 192: EARLY FIELD TRIAL Setting Display S
- Page 193 and 194: EARLY FIELD TRIAL Raw Capture Mode
- Page 195 and 196: EARLY FIELD TRIAL Table 8-9. Summar
- Page 197 and 198: EARLY FIELD TRIAL Raw Capture Mode
- Page 199 and 200: EARLY FIELD TRIAL Searching for Fra
- Page 201 and 202: EARLY FIELD TRIAL Raw Capture Mode
- Page 203 and 204: EARLY FIELD TRIAL Raw Capture Mode
- Page 205 and 206: EARLY FIELD TRIAL Raw Capture Mode
- Page 207 and 208: EARLY FIELD TRIAL Printing Decoded
- Page 209 and 210: EARLY FIELD TRIAL Using the Matrix
- Page 211 and 212: EARLY FIELD TRIAL Raw Capture Mode
- Page 213 and 214: EARLY FIELD TRIAL Using the Host Ta
- Page 215 and 216: EARLY FIELD TRIAL Using the Protoco
- Page 217 and 218: EARLY FIELD TRIAL Enabling VLAN Dat
- Page 219 and 220: EARLY FIELD TRIAL Expert Analysis O
- Page 221 and 222: EARLY FIELD TRIAL Expert Tool Bar T
EARLY FIELD TRIAL<br />
Types of Display Filters<br />
Raw Capture <strong>Mode</strong> Postcapture Analysis<br />
<strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong> provides several types of display<br />
filters:<br />
NOTE: Display filters are separate from Quick Select window filters.<br />
Refer to Using Filters in the Quick Select Window on page 119 for<br />
information on how to create Quick Select window filters and apply<br />
them as source, mining, and statistics filters.<br />
Table 8-6. <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong> Display Filters<br />
Filter Type Description<br />
Automatic Display Filters<br />
Using Automatic Display<br />
Filters on page 174<br />
Quick Display Filters<br />
Using Quick Filters on page<br />
178<br />
Manual Display Filters<br />
(Display > Define Filter)<br />
Using Manual Filters (Display<br />
> Define Filter) on page 183<br />
Expert Display Filters<br />
Setting Automatic Expert<br />
Display Filters on page 222<br />
You can automatically populate the Define Filter - Display dialog<br />
box’s tabs with filter settings based on selected portions of the<br />
currently selected packet in the Decode tab. You do this by using<br />
the dropdown at the top of the Decode tab to specify which portion<br />
of the selected packet you want to use as a filter (for example, just<br />
the source IP address) and clicking the Define Display Filter<br />
button.<br />
Quick Display Filters are similar to automatic display filters – they<br />
filter the active Decode tab based on selected portions of the<br />
currently selected packet in the Decode tab. The main difference is<br />
that they take effect immediately without displaying the Define<br />
Filter dialog box first.<br />
You set Quick Filters by using the dropdown at the top of the<br />
Decode tab to specify which portion of the selected packet you<br />
want to use as a filter (for example, just the source port) and<br />
clicking the Quick Filter button.<br />
Note: You set global options for how Quick Filters are applied in the<br />
Display > Display Setup > Packet Selection tab. These options<br />
specify to which packets Quick Filters should be applied (all or<br />
selected) and how results should be returned (by selecting/clearing<br />
packets in the active tab or by showing a new filtered tab at the<br />
base of the postcapture display window).<br />
You can set Display filters manually in the Define Filter - Display<br />
dialog box. This dialog box is available by using the Display ><br />
Define Filter command. Then, you have full access to the<br />
standard Define Filter tabs described in Using Manual Filters<br />
(Display > Define Filter) on page 183.<br />
You can also set automatic Expert filters that only display data<br />
associated with a particular network object, symptom, or diagnosis.<br />
You do this by displaying the Expert tab, selecting an object,<br />
symptom, or diagnosis and clicking the Display Filter button.<br />
User’s Guide 173