Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout
Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout
EARLY FIELD TRIAL Chapter 1 Using Traditional Packet Capture 18 Sniffer Adaptive Application Analyzer In addition to the new Adaptive capture mode, the Expert analysis and raw packet decodes traditionally available in Sniffer products are also available in Sniffer Adaptive Application Analyzer. You can change the capture mode by clicking the Configure Capture button in the Capture toolbar and setting Capture Type to Raw instead of Adaptive (the default; Figure 1-4). Select the Capture Mode in the Configure Capture dialog box. Figure 1-4. Setting the Capture Mode Protocols Supported for Sniffer Adaptive Processing Sniffer Adaptive Application Analyzer supports the following protocols for adaptive processing, storing ASPs with derived payloads. For all other protocols, you have the choice of capturing full packets, sliced packets, or filtering them out entirely. HTTP FTP DNS SMTP POP3 RTP RTCP SIP Cisco Skinny
EARLY FIELD TRIAL Sample Trace Files What’s Different? Sniffer Adaptive Application Analyzer Overview Sniffer Adaptive Application Analyzer is provided with several sets of sample trace files in the \Netscout\Sniffer Adaptive Application Analyzer\traces folder. Each set contains both a raw packet capture (.cap) file and the corresponding Adaptive Traces (.asp/.asr) generated by replaying the capture file. Each raw packet capture file contains flows using the protocols supported for ASI processing listed above. This way, you can compare the raw packet file and its corresponding Adaptive Session files to understand how the ASI technology works. In particular, you can see how Adaptive Intelligence stores key elements of supported protocols. For example, the key elements captured for a HTTP flow are Host and URL details, while for a RTP flow, the Caller and Callee Media Addresses are stored. The sample trace files also demonstrate the compression achieved by Adaptive processing – you can see at a glance the size differences between the raw and Adaptive traces. Sniffer Adaptive Application Analyzer’s Adaptive mode combines a modified version of the InfiniStream Console user interface with the local network interface and packet buffer familiar to users of Sniffer Portable Professional and Sniffer Global Application. This section summarizes some of the differences users of those products will notice as they work with Sniffer Adaptive Application Analyzer in Adaptive mode. Key Differences for InfiniStream Console Users Users accustomed to working with the InfiniStream Console will notice some key differences in Sniffer Adaptive Application Analyzer. Most of the differences are due to the differences in how capture/monitoring takes place – rather than operating as a unified Console with connections to multiple persistent stream-to-disk interfaces on remote InfiniStream appliances, Sniffer Adaptive Application Analyzer uses a single local Ethernet interface capturing data to a local buffer. Key differences between Sniffer Adaptive Application Analyzer and the InfiniStream Console summarized below: User’s Guide 19
- Page 1 and 2: EARLY FIELD TRIAL Sniffer ® Adapti
- Page 3 and 4: EARLY FIELD TRIAL "This product inc
- Page 5 and 6: EARLY FIELD TRIAL Contents Section
- Page 7 and 8: EARLY FIELD TRIAL Contents Overview
- Page 9 and 10: EARLY FIELD TRIAL Contents Setting
- Page 11 and 12: EARLY FIELD TRIAL SECTION 1 Introdu
- Page 13 and 14: EARLY FIELD TRIAL Sniffer Adaptive
- Page 15 and 16: EARLY FIELD TRIAL Figure 1-2. Adapt
- Page 17: EARLY FIELD TRIAL Sniffer Adaptive
- Page 21 and 22: EARLY FIELD TRIAL Sniffer Adaptive
- Page 23 and 24: EARLY FIELD TRIAL Key Terms Table 1
- Page 25 and 26: EARLY FIELD TRIAL Table 1-3. Key Te
- Page 27 and 28: EARLY FIELD TRIAL Quick Start - Fiv
- Page 29 and 30: EARLY FIELD TRIAL Double-click the
- Page 31 and 32: EARLY FIELD TRIAL Quick Start - Fiv
- Page 33 and 34: EARLY FIELD TRIAL Step 4 - Capturin
- Page 35 and 36: EARLY FIELD TRIAL Capture Mode Adap
- Page 37 and 38: EARLY FIELD TRIAL Step 5 - Mining P
- Page 39 and 40: EARLY FIELD TRIAL Adaptive Postcapt
- Page 41 and 42: EARLY FIELD TRIAL Table 2-1. Postca
- Page 43 and 44: EARLY FIELD TRIAL SECTION 2 Getting
- Page 45 and 46: EARLY FIELD TRIAL Working with the
- Page 47 and 48: EARLY FIELD TRIAL Introducing the N
- Page 49 and 50: EARLY FIELD TRIAL Other Navigation
- Page 51 and 52: EARLY FIELD TRIAL Using the Time Se
- Page 53 and 54: EARLY FIELD TRIAL Working with the
- Page 55 and 56: EARLY FIELD TRIAL Zoom Menu Working
- Page 57 and 58: EARLY FIELD TRIAL Introducing the G
- Page 59 and 60: EARLY FIELD TRIAL Selected Statisti
- Page 61 and 62: EARLY FIELD TRIAL Pie Chart Working
- Page 63 and 64: EARLY FIELD TRIAL Column Chart Work
- Page 65 and 66: EARLY FIELD TRIAL Time Series Chart
- Page 67 and 68: EARLY FIELD TRIAL Working with the
EARLY FIELD TRIAL<br />
Sample Trace Files<br />
What’s Different?<br />
<strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong> Overview<br />
<strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong> is provided with several sets of<br />
sample trace files in the \Netscout\<strong>Sniffer</strong> <strong>Adaptive</strong><br />
<strong>Application</strong> <strong>Analyzer</strong>\traces folder. Each set contains both a raw packet<br />
capture (.cap) file and the corresponding <strong>Adaptive</strong> Traces (.asp/.asr)<br />
generated by replaying the capture file.<br />
Each raw packet capture file contains flows using the protocols<br />
supported for ASI processing listed above. This way, you can compare<br />
the raw packet file and its corresponding <strong>Adaptive</strong> Session files to<br />
understand how the ASI technology works.<br />
In particular, you can see how <strong>Adaptive</strong> Intelligence stores key elements<br />
of supported protocols. For example, the key elements captured for a<br />
HTTP flow are Host and URL details, while for a RTP flow, the Caller and<br />
Callee Media Addresses are stored. The sample trace files also<br />
demonstrate the compression achieved by <strong>Adaptive</strong> processing – you<br />
can see at a glance the size differences between the raw and <strong>Adaptive</strong><br />
traces.<br />
<strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong>’s <strong>Adaptive</strong> mode combines a<br />
modified version of the InfiniStream Console user interface with the local<br />
network interface and packet buffer familiar to users of <strong>Sniffer</strong> Portable<br />
Professional and <strong>Sniffer</strong> Global <strong>Application</strong>. This section summarizes<br />
some of the differences users of those products will notice as they work<br />
with <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong> in <strong>Adaptive</strong> mode.<br />
Key Differences for InfiniStream Console Users<br />
Users accustomed to working with the InfiniStream Console will notice<br />
some key differences in <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong>. Most of<br />
the differences are due to the differences in how capture/monitoring<br />
takes place – rather than operating as a unified Console with<br />
connections to multiple persistent stream-to-disk interfaces on remote<br />
InfiniStream appliances, <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong> uses a<br />
single local Ethernet interface capturing data to a local buffer.<br />
Key differences between <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong> and the<br />
InfiniStream Console summarized below:<br />
User’s Guide 19