Sniffer® Portable Professional User's Guide - NetScout
Sniffer® Portable Professional User's Guide - NetScout Sniffer® Portable Professional User's Guide - NetScout
Chapter 10 220 Sniffer Portable Professional In general, you work with Defined filters in the Define Filter dialog box. This section describes how to do that. Automatic filters. In some cases, filters are created automatically by Sniffer Portable Professional when you choose to view selected information. For example, you can single-out a particular station's conversations using the Visual Filter on the Matrix map display. You can also set automatic Expert Filters in many Expert window displays, as well as automatic Display filters from an active Decode tab. Automatic filters are described in the following sections: Automatic Display filters are described in Setting Display Filters on page 167. Expert filters are described in Setting Automatic Expert Display Filters on page 151 Define Filter Options for Wireless Networks Defining Filters When using Sniffer Portable Professional with a wireless adapter, the Define Filter dialog box adds several wireless-specific filtering options: The Define Filter dialog box’s Advanced tab includes wireless LAN packet types on which you can filter (for example, PLCP Errors). See Filters for 802.11 Packet Types in the Advanced Tab on page 237. The Define Filter dialog box also includes an 802.11 tab specifically for wireless LAN filtering. See Setting Filter Options in the 802.11 Tab on page 238. In general, you work with filters in the Define Filter dialog box. The type of filter is determined by its use: When selecting what traffic to monitor, the filter becomes a monitor filter. When selecting what traffic to admit into the capture buffer, the filter becomes a capture filter. When selecting what data in the capture buffer to display, the filter becomes a display filter.
Defining Filters and Triggers When you define a filter, you give it a name (known as a Profile in the application displays). You then select a filter Profile to use as a monitor, capture, or display filter (depending on whether you choose the Select Filter command from the Monitor, Capture, or Display menu). To easily differentiate different kinds of filters, use a distinctive naming convention. See Using Filter Profiles on page 222 for details. To access the Define Filter dialog box: 1 Select Define Filter from the Monitor, Capture, or Display menu. You can also click the button (located in many windows). The Define Filter dialog box lets you define capture filters to collect specific network information. When you first open the Define Filter dialog box, the Summary tab appears, summarizing the current settings for the selected filter. This tab also displays the buffer size and the buffer action (stop capture or overwrite older data when buffer is full). In addition to the Summary tab, some or all of the following tabs are available, depending on the type of network adapter in use: The Address tab lets you define filters to capture data transmitted between network nodes (or address pairs). The Port tab lets you filter traffic on IP or IPX ports. The Data Pattern tab lets you define filters that capture frames that match data patterns rules joined by AND/OR/NOT logical operators. Data pattern filters provide a generic method of defining and documenting filter conditions that can not be defined by the address and protocol filters. The Advanced tab tab lets you define filters that capture frames that belong to one or more protocol group(s). It also lets you set filters for frames falling in a specified size range and various protocol-specific frame types (for example, jabber packets on an Ethernet network). The Buffer tab lets you set various global options relating to the size of the capture buffer and what actions should be taken when the maximum size of the capture buffer is reached. You can also create filter profiles — saved combinations of one or more of the individual filters defined on the tabs listed above. See Using Filter Profiles on page 222 for details. User’s Guide 221
- Page 170 and 171: Chapter 8 b 170 Sniffer Portable Pr
- Page 172 and 173: Chapter 8 a 172 Sniffer Portable Pr
- Page 174 and 175: Chapter 8 174 Sniffer Portable Prof
- Page 176 and 177: Chapter 8 176 Sniffer Portable Prof
- Page 178 and 179: Chapter 8 178 Sniffer Portable Prof
- Page 180 and 181: Chapter 8 Display Setup > Summary D
- Page 182 and 183: Chapter 8 182 Sniffer Portable Prof
- Page 184 and 185: Chapter 8 184 Sniffer Portable Prof
- Page 186 and 187: Chapter 8 Searching for Frames in t
- Page 188 and 189: Chapter 8 Searching for Frames Matc
- Page 190 and 191: Chapter 8 Searching for Frames Matc
- Page 192 and 193: Chapter 8 Searching for Data Patter
- Page 194 and 195: Chapter 8 194 Sniffer Portable Prof
- Page 196 and 197: Chapter 8 Printing Decoded Packets
- Page 198 and 199: Chapter 8 Using Protocol Forcing Yo
- Page 200 and 201: Chapter 8 Sniffer Portable Professi
- Page 202 and 203: Chapter 8 Postcapture Matrix Tab 20
- Page 204 and 205: Chapter 8 More about the Matrix Tra
- Page 206 and 207: Chapter 8 Postcapture Host Table Ta
- Page 208 and 209: Chapter 8 Postcapture Protocol Dist
- Page 210 and 211: Chapter 8 Postcapture Statistics Ta
- Page 212 and 213: Chapter 8 212 Sniffer Portable Prof
- Page 214 and 215: Chapter 9 4 Click OK. 214 Sniffer P
- Page 216 and 217: Chapter 9 216 Sniffer Portable Prof
- Page 218 and 219: Chapter 9 218 Sniffer Portable Prof
- Page 222 and 223: Chapter 10 Using a Defined Filter U
- Page 224 and 225: Chapter 10 224 Sniffer Portable Pro
- Page 226 and 227: Chapter 10 Drag and drop a symbolic
- Page 228 and 229: Chapter 10 Setting Filter Options i
- Page 230 and 231: Chapter 10 Setting Filter Options i
- Page 232 and 233: Chapter 10 Add or Edit Pattern Dial
- Page 234 and 235: Chapter 10 234 Sniffer Portable Pro
- Page 236 and 237: Chapter 10 Specify one or more netw
- Page 238 and 239: Chapter 10 Setting Filter Options i
- Page 240 and 241: Chapter 10 240 Sniffer Portable Pro
- Page 242 and 243: Chapter 10 242 Sniffer Portable Pro
- Page 244 and 245: Chapter 10 244 Sniffer Portable Pro
- Page 246 and 247: Chapter 10 5 Click OK. 246 Sniffer
- Page 248 and 249: Chapter 10 248 Sniffer Portable Pro
- Page 250 and 251: Chapter 11 Description 250 Sniffer
- Page 252 and 253: Chapter 11 Entering Names Manually
- Page 254 and 255: Chapter 11 Click to resolve the Dom
- Page 256 and 257: Chapter 11 256 Sniffer Portable Pro
- Page 258 and 259: Chapter 12 Type of node triggering
- Page 260 and 261: Chapter 12 Setting Alarm Severity L
- Page 262 and 263: Chapter 12 Logging and Severities f
- Page 264 and 265: Chapter 12 Setting Alarm Notificati
- Page 266 and 267: Chapter 12 266 Sniffer Portable Pro
- Page 268 and 269: Chapter 13 268 Sniffer Portable Pro
Chapter 10<br />
220 Sniffer <strong>Portable</strong> <strong>Professional</strong><br />
In general, you work with Defined filters in the Define Filter dialog<br />
box. This section describes how to do that.<br />
Automatic filters. In some cases, filters are created automatically<br />
by Sniffer <strong>Portable</strong> <strong>Professional</strong> when you choose to view selected<br />
information. For example, you can single-out a particular station's<br />
conversations using the Visual Filter on the Matrix map display. You<br />
can also set automatic Expert Filters in many Expert window<br />
displays, as well as automatic Display filters from an active Decode<br />
tab.<br />
Automatic filters are described in the following sections:<br />
Automatic Display filters are described in Setting Display<br />
Filters on page 167.<br />
Expert filters are described in Setting Automatic Expert<br />
Display Filters on page 151<br />
Define Filter Options for Wireless Networks<br />
Defining Filters<br />
When using Sniffer <strong>Portable</strong> <strong>Professional</strong> with a wireless adapter, the<br />
Define Filter dialog box adds several wireless-specific filtering options:<br />
The Define Filter dialog box’s Advanced tab includes wireless LAN<br />
packet types on which you can filter (for example, PLCP Errors).<br />
See Filters for 802.11 Packet Types in the Advanced Tab on page<br />
237.<br />
The Define Filter dialog box also includes an 802.11 tab specifically<br />
for wireless LAN filtering. See Setting Filter Options in the 802.11<br />
Tab on page 238.<br />
In general, you work with filters in the Define Filter dialog box. The type<br />
of filter is determined by its use:<br />
When selecting what traffic to monitor, the filter becomes a<br />
monitor filter.<br />
When selecting what traffic to admit into the capture buffer, the<br />
filter becomes a capture filter.<br />
When selecting what data in the capture buffer to display, the filter<br />
becomes a display filter.