Sniffer® Portable Professional User's Guide - NetScout
Sniffer® Portable Professional User's Guide - NetScout Sniffer® Portable Professional User's Guide - NetScout
Chapter 8 Table 8-3. Decode Tab Toolbar Buttons Button Title Description Automatic Filter Type Selection 166 Sniffer Portable Professional Use this dropdown to specify which information in the currently selected packet should be used to automatically populate the Define Filter dialog box’s fields when you click the Define Display Filter or Add to Last Filter button. You can populate based on source/destination IP addresses, ports, and MAC addresses. See Using Automatic Display Filters on page 168. Define Display Filter Displays the Define Filter dialog box with settings automatically populated based on the currently selected packet and the setting of the adjacent Filter Type Selection dropdown. See Using Automatic Display Filters on page 168. Add to Last Filter Takes the type of information specified in the Filter Type Selection dropdown from the currently selected packet and adds it to the last filter used in the Define Filter dialog. See Combining Filter Components (“Add to Last Filter”) on page 173 for details. Quick Filter Automatically filters the display based on the selected information in the currently selected packet. For example, if the Filter Type Selection dropdown is set to Connection, clicking Quick Filter will filter the display based on the source/destination addresses and ports (that is, the connection). Use the Display > Display Setup > Packet Selection tab to specify how Quick Filters will be applied (for example, whether matching packets are returned in a new tab or shown selected in the active tab, and so on). See Using Quick Filters on page 172 for details.
Setting Display Filters Displaying Captured Data A filter applied to the display of captured data is called a display filter. Display filters let you select the packets you want to display in a Decode tab. Display filters do not affect the contents of the capture buffer. They just prevent some of the data from being displayed. You can use display filters to view only: Packets transmitted between network nodes (or address pairs) Packets that belong to one or more protocol groups Packets that match predefined data patterns Error packets Packets that belong to a certain size range Packets that match various combinations of the above specifications IMPORTANT: Defining Filters and Triggers on page 219 provides the details on working with Sniffer filters in general – monitor, capture, and display. This section adds to that information with some additional topics specifically for display filters. Types of Display Filters The Sniffer provides several types of display filters: Manual Display Filters You can set Display filters manually in the Define Filter - Display dialog box. This dialog box is available by using the Display > Define Filter command. Then, you have full access to the standard Define Filter tabs described in Defining Filters and Triggers on page 219. Automatic Display Filters You can automatically populate the Define Filter - Display dialog box’s tabs with filter settings based on selected portions of the currently selected packet in the Decode tab. You do this by using the dropdown at the top of the Decode tab to specify which portion of the selected packet you want to use as a filter (for example, just the source IP address) and clicking the Define Display Filter button. See Using Automatic Display Filters on page 168. User’s Guide 167
- Page 116 and 117: Chapter 5 Global Statistics 116 Sni
- Page 118 and 119: Chapter 5 118 Sniffer Portable Prof
- Page 120 and 121: Chapter 5 Monitor Alarms 120 Sniffe
- Page 122 and 123: Chapter 6 Capture Controls 122 Snif
- Page 124 and 125: Chapter 6 Capture Buffer 124 Sniffe
- Page 126 and 127: Chapter 6 Tips: 126 Sniffer Portabl
- Page 128 and 129: Chapter 6 Capturing from Specific S
- Page 130 and 131: Chapter 6 130 Sniffer Portable Prof
- Page 132 and 133: Chapter 7 132 Sniffer Portable Prof
- Page 134 and 135: Chapter 7 Setting Expert Options 13
- Page 136 and 137: Chapter 7 136 Sniffer Portable Prof
- Page 138 and 139: Chapter 7 Expert Subnet Mask Settin
- Page 140 and 141: Chapter 7 140 Sniffer Portable Prof
- Page 142 and 143: Chapter 7 142 Sniffer Portable Prof
- Page 144 and 145: Chapter 7 Discovered access points
- Page 146 and 147: Chapter 7 146 Sniffer Portable Prof
- Page 148 and 149: Chapter 7 148 Sniffer Portable Prof
- Page 150 and 151: Chapter 7 Expert Oracle Options 150
- Page 152 and 153: Chapter 7 Limitations of the Expert
- Page 154 and 155: Chapter 7 Click to show the packet
- Page 156 and 157: Chapter 7 156 Sniffer Portable Prof
- Page 158 and 159: Chapter 8 Displaying Captured Packe
- Page 160 and 161: Chapter 8 Postcapture Views for Wir
- Page 162 and 163: Chapter 8 162 Sniffer Portable Prof
- Page 164 and 165: Chapter 8 164 Sniffer Portable Prof
- Page 168 and 169: Chapter 8 168 Sniffer Portable Prof
- Page 170 and 171: Chapter 8 b 170 Sniffer Portable Pr
- Page 172 and 173: Chapter 8 a 172 Sniffer Portable Pr
- Page 174 and 175: Chapter 8 174 Sniffer Portable Prof
- Page 176 and 177: Chapter 8 176 Sniffer Portable Prof
- Page 178 and 179: Chapter 8 178 Sniffer Portable Prof
- Page 180 and 181: Chapter 8 Display Setup > Summary D
- Page 182 and 183: Chapter 8 182 Sniffer Portable Prof
- Page 184 and 185: Chapter 8 184 Sniffer Portable Prof
- Page 186 and 187: Chapter 8 Searching for Frames in t
- Page 188 and 189: Chapter 8 Searching for Frames Matc
- Page 190 and 191: Chapter 8 Searching for Frames Matc
- Page 192 and 193: Chapter 8 Searching for Data Patter
- Page 194 and 195: Chapter 8 194 Sniffer Portable Prof
- Page 196 and 197: Chapter 8 Printing Decoded Packets
- Page 198 and 199: Chapter 8 Using Protocol Forcing Yo
- Page 200 and 201: Chapter 8 Sniffer Portable Professi
- Page 202 and 203: Chapter 8 Postcapture Matrix Tab 20
- Page 204 and 205: Chapter 8 More about the Matrix Tra
- Page 206 and 207: Chapter 8 Postcapture Host Table Ta
- Page 208 and 209: Chapter 8 Postcapture Protocol Dist
- Page 210 and 211: Chapter 8 Postcapture Statistics Ta
- Page 212 and 213: Chapter 8 212 Sniffer Portable Prof
- Page 214 and 215: Chapter 9 4 Click OK. 214 Sniffer P
Setting Display Filters<br />
Displaying Captured Data<br />
A filter applied to the display of captured data is called a display filter.<br />
Display filters let you select the packets you want to display in a Decode<br />
tab. Display filters do not affect the contents of the capture buffer. They<br />
just prevent some of the data from being displayed.<br />
You can use display filters to view only:<br />
Packets transmitted between network nodes (or address pairs)<br />
Packets that belong to one or more protocol groups<br />
Packets that match predefined data patterns<br />
Error packets<br />
Packets that belong to a certain size range<br />
Packets that match various combinations of the above<br />
specifications<br />
IMPORTANT: Defining Filters and Triggers on page 219 provides the<br />
details on working with Sniffer filters in general – monitor, capture, and<br />
display. This section adds to that information with some additional topics<br />
specifically for display filters.<br />
Types of Display Filters<br />
The Sniffer provides several types of display filters:<br />
Manual Display Filters<br />
You can set Display filters manually in the Define Filter - Display dialog<br />
box. This dialog box is available by using the Display > Define Filter<br />
command. Then, you have full access to the standard Define Filter tabs<br />
described in Defining Filters and Triggers on page 219.<br />
Automatic Display Filters<br />
You can automatically populate the Define Filter - Display dialog box’s<br />
tabs with filter settings based on selected portions of the currently<br />
selected packet in the Decode tab. You do this by using the dropdown at<br />
the top of the Decode tab to specify which portion of the selected packet<br />
you want to use as a filter (for example, just the source IP address) and<br />
clicking the Define Display Filter button.<br />
See Using Automatic Display Filters on page 168.<br />
User’s <strong>Guide</strong> 167