Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout

Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout

10.03.2013 Views

EARLY FIELD TRIAL Chapter 9 222 Sniffer Adaptive Application Analyzer Figure 9-2. Rearranging the Expert Tab Panes Setting Automatic Expert Display Filters You can use Expert display filters to automatically display all traffic in the capture buffer related to a specific: Network object Symptom or diagnosis You apply an Expert display filter by selecting a network object, symptom, or diagnosis in the summary pane of the Expert window and clicking the Define Filter button in the upper left corner of the Expert window. In response, the Expert adds a new tab to the display window (titled Filtered xx, where xx is the sequential number of the filter you applied) containing just those frames associated with the selected network object, symptom, or diagnosis. The frames may be displayed with skipped frame numbers on the Filtered tab, because the network object filter does not change the frame numbers of frames it selects for display. Thus, you may see frame 30 followed by frame 35 because the network object filter excluded frames 31-34. If you save the filtered frames as a new file (using the Save As) command, the filtered frames will be renumbered sequentially. Limitations of the Expert Filter The Expert filter has some limitations: a b

EARLY FIELD TRIAL Expert Analysis Some symptoms and diagnoses, such as Broadcast storm, have no associated network object on which the analyzer can filter. In those cases, the Define Filter button will not appear at the upper left of the display, indicating that an Expert filter cannot be set. Occasionally you will see the message: No frames matched the filter. This message appears when one or more of the following conditions exist: The highlighted object has not sent or received a frame. The highlighted object has been filtered out by a standard Display filter. There are no longer any frames in the buffer associated with the object because the capture buffer has wrapped. During a capture in which the buffer is set to wrap, some of the frames the Expert used to create network objects will pass out of the capture buffer to make room for new frames. Setting an Expert filter on such an object can result in no frames being available for display. Other Notes About Expert Filters The Expert analyzer uses several algorithms to decide which frames are associated with a network object. Sometimes, these algorithms may eliminate frames you consider relevant. Certain maintenance frames may not be shown. For example, if you set an Expert filter on a Novell Netware connection-layer connection, the Expert analyzer would show all those related frames with NCP layers, but would not show certain connection maintenance frames it considers irrelevant. When you set a filter on a connection object, the frame that initiates the connection is not shown. This is because Expert does not create a connection object until the connection is completed. When you filter on an application object, TCP continuation frames are not shown. Displaying Context-Sensitive Explain Messages The Expert provides an explanation of the information in each pane of the Expert window. Click inside the pane on which you need information and press F1. User’s Guide 223

EARLY FIELD TRIAL Chapter 9<br />

222 <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong><br />

Figure 9-2. Rearranging the Expert Tab Panes<br />

Setting Automatic Expert Display Filters<br />

You can use Expert display filters to automatically display all traffic in the<br />

capture buffer related to a specific:<br />

Network object<br />

Symptom or diagnosis<br />

You apply an Expert display filter by selecting a network object,<br />

symptom, or diagnosis in the summary pane of the Expert window and<br />

clicking the Define Filter button in the upper left corner of the Expert<br />

window. In response, the Expert adds a new tab to the display window<br />

(titled Filtered xx, where xx is the sequential number of the filter you<br />

applied) containing just those frames associated with the selected<br />

network object, symptom, or diagnosis.<br />

The frames may be displayed with skipped frame numbers on the<br />

Filtered tab, because the network object filter does not change the<br />

frame numbers of frames it selects for display. Thus, you may see frame<br />

30 followed by frame 35 because the network object filter excluded<br />

frames 31-34. If you save the filtered frames as a new file (using the<br />

Save As) command, the filtered frames will be renumbered<br />

sequentially.<br />

Limitations of the Expert Filter<br />

The Expert filter has some limitations:<br />

a<br />

b

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!