Sniffer® Portable Professional User's Guide - NetScout

Sniffer® Portable Professional User's Guide - NetScout Sniffer® Portable Professional User's Guide - NetScout

10.03.2013 Views

Chapter 8 Searching for Data Patterns using a Pattern from a Known Packet 192 Sniffer Portable Professional In addition to Searching for Frames Matching Data Patterns, the easiest way to search for a data pattern is to use a pattern from a known packet. To search for data patterns using a pattern from a known packet: 1 Locate and highlight either: A packet in the Summary pane. A protocol field or a data pattern in the Detail pane. 2 Open the Find Frame dialog box by selecting the Find Frame command from the Display menu (or from the context menu). 3 Select the Data tab. If you selected a packet in the Summary pane, the Data tab will already contain some data from the selected packet. If you selected a protocol field or data pattern in the Detail pane, the Data tab will already contain the selected field or pattern. 4 Set the From list box to Don’t Care. 5 You can click the Set Data button to open the Set Data dialog box, containing a line-by-line decode of the selected packet. Figure 8-14. The Set Data Dialog Box 6 Select a line from the Set Data dialog box and click OK. 7 The data from the selected line is placed in the data pattern area of the Find Frame dialog box. Adjust the data and the length if necessary

Displaying Captured Data 8 Click OK to start the search. If a pattern match is found, the packet containing the pattern will be displayed in the Decode Display. Press F3 to search for the next packet. Searching for Frames Matching Packet Status Flags To search for packets with a a particular Status flag: 1 Display the Find Frame dialog box using any of the following commands: Select Find Frame from the Display menu. Select Find Frame from the Decode tab’s context menu (activated by right-clicking anywhere on the Decode tab). Use the Alt-F3 keyboard shortcut. 2 Click the Status tab. 3 Select the status flag(s) to search for. 4 Click Up or Down to specify the search direction. 5 Click OK. If a frame with one of the specified flags is found, the frame containing the will be displayed in the Decode Display. Press F3 to search for the next packet matching the same criteria. NOTE: Some Status flags require an enhanced driver to detect. Because Sniffer Portable Professional no longer includes enhanced drivers for Ethernet, searching for the corresponding Status flag will often produce no results. For descriptions of the various possible packet status flags, see Packet Status Flags in the Summary Pane on page 185. User’s Guide 193

Chapter 8<br />

Searching for Data Patterns using a Pattern from a Known<br />

Packet<br />

192 Sniffer <strong>Portable</strong> <strong>Professional</strong><br />

In addition to Searching for Frames Matching Data Patterns, the easiest<br />

way to search for a data pattern is to use a pattern from a known packet.<br />

To search for data patterns using a pattern from a known<br />

packet:<br />

1 Locate and highlight either:<br />

A packet in the Summary pane.<br />

A protocol field or a data pattern in the Detail pane.<br />

2 Open the Find Frame dialog box by selecting the Find Frame<br />

command from the Display menu (or from the context menu).<br />

3 Select the Data tab.<br />

If you selected a packet in the Summary pane, the Data tab<br />

will already contain some data from the selected packet.<br />

If you selected a protocol field or data pattern in the Detail<br />

pane, the Data tab will already contain the selected field or<br />

pattern.<br />

4 Set the From list box to Don’t Care.<br />

5 You can click the Set Data button to open the Set Data dialog box,<br />

containing a line-by-line decode of the selected packet.<br />

Figure 8-14. The Set Data Dialog Box<br />

6 Select a line from the Set Data dialog box and click OK.<br />

7 The data from the selected line is placed in the data pattern area<br />

of the Find Frame dialog box. Adjust the data and the length if<br />

necessary

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!