Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout
Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout
EARLY FIELD TRIAL Chapter 9 222 Sniffer Adaptive Application Analyzer Figure 9-2. Rearranging the Expert Tab Panes Setting Automatic Expert Display Filters You can use Expert display filters to automatically display all traffic in the capture buffer related to a specific: Network object Symptom or diagnosis You apply an Expert display filter by selecting a network object, symptom, or diagnosis in the summary pane of the Expert window and clicking the Define Filter button in the upper left corner of the Expert window. In response, the Expert adds a new tab to the display window (titled Filtered xx, where xx is the sequential number of the filter you applied) containing just those frames associated with the selected network object, symptom, or diagnosis. The frames may be displayed with skipped frame numbers on the Filtered tab, because the network object filter does not change the frame numbers of frames it selects for display. Thus, you may see frame 30 followed by frame 35 because the network object filter excluded frames 31-34. If you save the filtered frames as a new file (using the Save As) command, the filtered frames will be renumbered sequentially. Limitations of the Expert Filter The Expert filter has some limitations: a b
EARLY FIELD TRIAL Expert Analysis Some symptoms and diagnoses, such as Broadcast storm, have no associated network object on which the analyzer can filter. In those cases, the Define Filter button will not appear at the upper left of the display, indicating that an Expert filter cannot be set. Occasionally you will see the message: No frames matched the filter. This message appears when one or more of the following conditions exist: The highlighted object has not sent or received a frame. The highlighted object has been filtered out by a standard Display filter. There are no longer any frames in the buffer associated with the object because the capture buffer has wrapped. During a capture in which the buffer is set to wrap, some of the frames the Expert used to create network objects will pass out of the capture buffer to make room for new frames. Setting an Expert filter on such an object can result in no frames being available for display. Other Notes About Expert Filters The Expert analyzer uses several algorithms to decide which frames are associated with a network object. Sometimes, these algorithms may eliminate frames you consider relevant. Certain maintenance frames may not be shown. For example, if you set an Expert filter on a Novell Netware connection-layer connection, the Expert analyzer would show all those related frames with NCP layers, but would not show certain connection maintenance frames it considers irrelevant. When you set a filter on a connection object, the frame that initiates the connection is not shown. This is because Expert does not create a connection object until the connection is completed. When you filter on an application object, TCP continuation frames are not shown. Displaying Context-Sensitive Explain Messages The Expert provides an explanation of the information in each pane of the Expert window. Click inside the pane on which you need information and press F1. User’s Guide 223
- Page 171 and 172: EARLY FIELD TRIAL Table 8-5. Decode
- Page 173 and 174: EARLY FIELD TRIAL Types of Display
- Page 175 and 176: EARLY FIELD TRIAL Raw Capture Mode
- Page 177 and 178: EARLY FIELD TRIAL a The “Apply on
- Page 179 and 180: EARLY FIELD TRIAL Raw Capture Mode
- Page 181 and 182: EARLY FIELD TRIAL Raw Capture Mode
- Page 183 and 184: EARLY FIELD TRIAL Raw Capture Mode
- Page 185 and 186: EARLY FIELD TRIAL Using the Manual
- Page 187 and 188: EARLY FIELD TRIAL 5 Click OK. Figur
- Page 189 and 190: EARLY FIELD TRIAL Raw Capture Mode
- Page 191 and 192: EARLY FIELD TRIAL Setting Display S
- Page 193 and 194: EARLY FIELD TRIAL Raw Capture Mode
- Page 195 and 196: EARLY FIELD TRIAL Table 8-9. Summar
- Page 197 and 198: EARLY FIELD TRIAL Raw Capture Mode
- Page 199 and 200: EARLY FIELD TRIAL Searching for Fra
- Page 201 and 202: EARLY FIELD TRIAL Raw Capture Mode
- Page 203 and 204: EARLY FIELD TRIAL Raw Capture Mode
- Page 205 and 206: EARLY FIELD TRIAL Raw Capture Mode
- Page 207 and 208: EARLY FIELD TRIAL Printing Decoded
- Page 209 and 210: EARLY FIELD TRIAL Using the Matrix
- Page 211 and 212: EARLY FIELD TRIAL Raw Capture Mode
- Page 213 and 214: EARLY FIELD TRIAL Using the Host Ta
- Page 215 and 216: EARLY FIELD TRIAL Using the Protoco
- Page 217 and 218: EARLY FIELD TRIAL Enabling VLAN Dat
- Page 219 and 220: EARLY FIELD TRIAL Expert Analysis O
- Page 221: EARLY FIELD TRIAL Expert Tool Bar T
- Page 225 and 226: EARLY FIELD TRIAL Setting Expert Op
- Page 227 and 228: EARLY FIELD TRIAL Analyze Expert An
- Page 229 and 230: EARLY FIELD TRIAL Alarms Expert Ana
- Page 231 and 232: EARLY FIELD TRIAL Protocols To conf
- Page 233 and 234: EARLY FIELD TRIAL Subnet Masks To d
- Page 235 and 236: EARLY FIELD TRIAL To configure or d
- Page 237 and 238: EARLY FIELD TRIAL Oracle Options Mo
- Page 239 and 240: EARLY FIELD TRIAL IP Options Expert
- Page 241 and 242: EARLY FIELD TRIAL SECTION 4 Additio
- Page 243 and 244: EARLY FIELD TRIAL Setting Quick Sel
- Page 245 and 246: EARLY FIELD TRIAL Setting Quick Sel
- Page 247 and 248: EARLY FIELD TRIAL Setting Graph Tab
- Page 249 and 250: EARLY FIELD TRIAL Setting Quick Sel
- Page 251 and 252: EARLY FIELD TRIAL Setting Quick Sel
- Page 253 and 254: EARLY FIELD TRIAL Figure 10-6. Addi
- Page 255 and 256: EARLY FIELD TRIAL Using the Address
- Page 257 and 258: EARLY FIELD TRIAL Using the Address
- Page 259 and 260: EARLY FIELD TRIAL SECTION 5 Reporti
- Page 261 and 262: EARLY FIELD TRIAL Running Reports O
- Page 263 and 264: EARLY FIELD TRIAL Table 12-1. Sprea
- Page 265 and 266: EARLY FIELD TRIAL Running Reports 4
- Page 267 and 268: EARLY FIELD TRIAL Index A About the
- Page 269 and 270: EARLY FIELD TRIAL Host Table, 212 m
- Page 271 and 272: EARLY FIELD TRIAL G General tab, 24
EARLY FIELD TRIAL Chapter 9<br />
222 <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong><br />
Figure 9-2. Rearranging the Expert Tab Panes<br />
Setting Automatic Expert Display Filters<br />
You can use Expert display filters to automatically display all traffic in the<br />
capture buffer related to a specific:<br />
Network object<br />
Symptom or diagnosis<br />
You apply an Expert display filter by selecting a network object,<br />
symptom, or diagnosis in the summary pane of the Expert window and<br />
clicking the Define Filter button in the upper left corner of the Expert<br />
window. In response, the Expert adds a new tab to the display window<br />
(titled Filtered xx, where xx is the sequential number of the filter you<br />
applied) containing just those frames associated with the selected<br />
network object, symptom, or diagnosis.<br />
The frames may be displayed with skipped frame numbers on the<br />
Filtered tab, because the network object filter does not change the<br />
frame numbers of frames it selects for display. Thus, you may see frame<br />
30 followed by frame 35 because the network object filter excluded<br />
frames 31-34. If you save the filtered frames as a new file (using the<br />
Save As) command, the filtered frames will be renumbered<br />
sequentially.<br />
Limitations of the Expert Filter<br />
The Expert filter has some limitations:<br />
a<br />
b