Protocol Analyzer
Working with Captured Packets
5967–9446 395
To post-filter captured packets
1 Attach to an instance or load a trace file to post filter.
2 Specify a filter with the Filter menu as needed.
3 Choose Instance➤Post Filter.
You can post-filter packets captured in an instance or saved in a trace
file. This feature lets you create an instance according to one set of cap-
ture and filter criteria, then process that instance’s data into another
instance for further analysis according to a different set of criteria. The
target instance data is stored in memory on the Protocol Analyzer.
This technique is useful, for example, when you want to use a filter that
is too complex (requires too many filter table entries) for an RMON data
source. You can configure one instance to capture from the data source
using a simple filter, then post-filter that instance’s captured packets
through the complex filter.
When you choose Instance➤Post Filter, a snapshot of the source
instance’s capture buffer is processed in a new post-filter instance, called
filtered-data. The base window indicates the name of the source instance
or trace file, along with the notation “(post-filtered).” The packet decodes
window identifies that the packets are from “Playback” data.
If you are post-filtering a live instance, you can reattach to the original
instance by choosing Instance➤Attach… If you are post-filtering a trace
file, you can view the original file by reloading it with File➤Load Data…
When you post-filter a live instance that is still capturing data, packets
captured after choosing Instance➤Post Filter are not post-filtered. When
the target instance finishes processing the source data from the live in-
stance, you can repeat the post-filter steps to process a later snapshot of
the live data capture buffer.
The filtered-data instance, used to store the results of the post-filtering
operation, is deleted automatically when you exit Protocol Analyzer.
Post filtering requires the erm_netmd process, installed with the soft-
ware. Protocol Analyzer will start erm_netmd automatically, if is not
already running.
Comments to this Manuals