|
Lesson 1
Monitoring Network Traffic
6-11
■
Detail The decoded contents of the selected packet in the form of an expand-
able tree
■
Hexadecimal
The raw contents of the selected packet, in hexadecimal notation
The Detail pane is the most useful one in this display, as you can expand
any of the pro-
tocols in the packet to display the values of specific header fields, as
shown in Figure 6-6.
F06pm06
Figure 6-6
Network Monitor’s expandable protocol display
Using Capture and Display Filters
One of the things you learn quickly when using Network Monitor is that the
tool can
often provide an embarrassment of riches. Even a brief network traffic
sample can con-
tain hundreds of packets performing many different functions, and it can be
difficult to
home in on the information you need. However, Network Monitor provides the
ability
to filter the traffic you capture and display, so that you can concentrate
on specific
computers or protocols.
Network Monitor includes both capture and display filters. Capture filters
enable you to
specify which packets the program should copy to its buffer, and display
filters enable
you to control which packets already stored in the buffer the program
displays in the
Capture Summary window.
You use capture filters when you want to capture specific traffic to the
buffer over a
long period of time. For example, if you want to examine the traffic that a
server
|