Protocol Analyzer
Building a Filter
360 5967–9446
Building a Filter
One of the most powerful aspects of Protocol Analyzer is its comprehen-
sive filtering capabilities. Protocol Analyzer gives you two mechanisms
for specifying a packet capture filter:
● Filter component windows let you indicate filter criteria through a
graphical interface. The criteria you specify are converted to the Proto-
col Analyzer’s filter expression language.
● Filter expression language lets you build a filter expression directly by
specifying keywords, parameters, and logical operators.
In either case, the resulting filter is applied to the packets seen by the
data source, and only those packets passing the filter are captured.
Filter Component Windows
Filter component windows let you specify combinations of filter criteria
for host, protocol, packet size, packet status, and pattern matching.
Figure 74 on page 361 shows how the filter components are connected
logically when building the actual filter expression. A component that is
not specified is ignored.
When building a filter through the component windows, you can view the
corresponding filter expression language by selecting Filter➤
Expression… from the base window.
Availability
When capturing live data, a filter expression is converted to RMON filter
table entries. A Protocol Analyzer filter expression often requires many
filter table entries.
As such, it is possible to build a valid filter expression that cannot be
implemented due to insufficient resources on the data source. As a work-
around, simplify the filter specification or use post-filtering on the
management station, as discussed on page 395.
Comments to this Manuals