We are excited to announce the official release of Message Analyzer to the Microsoft Download Center. Sci-Fi movie references aside, this really is a new beginning for troubleshooting and analysis. Message Analyzer brings a set of new ideas, new techniques, and new paradigms in order to make analysis of protocols, log files, and system events a cohesive activity which allows correlation across all those types of traces.
As I detailed in the Network Capture is Dead blog, we have updated the way we capture messages. By leveraging ETW and providing inspection points to capture at the Firewall and HTTP Proxy layers, you can capture loopback and encrypted traffic that was not possible in the past. Message Analyzer also enables you to capture messages from multiple places in the system at the same time, collect them in one trace file and package up all the information so that it can be analyzed elsewhere.
There are also new ways to analyze and organize the trace data. Automatic diagnosis and coalescing of fragments and messages provide a concise and succinct view allowing you to focus on the problems and not the noise. New visualizations let you see a problem at a high level, and then dig in by viewing selected data in detail in the Analysis Grid. New tools like Sequence Matching, Viewpoints, and Grouping provide alternative ways to slice, dice and find the problems buried in heaps of noisy traces. Improved filtering syntax continues on where Network Monitor left and provides a richer way to specify fields and properties.
The world is full of many specialized areas each with their own silos of knowledge. Subject matter experts need a way to share this expertise so that everybody can benefit and learn from the masters. The sharing infrastructure is the starting place for this new innovation which will continue to evolve. Designed to allow users to manage and share various Message Analyzer assets like filters, views, trace scenarios and more, expert knowledge will become easier to discover and use.
The new name, Message Analyzer, reflects the broader initiative to analyze more than just network packet captures. Now your text files, event logs, and system event traces can be included altogether. When you analyze the merged traces the combined data helps provide an extra level of inspection and insight. And while this is the end of one chapter, it is only the start of a story that we will continue to share at a rapid pace. So please download Message Analyzer take it for a spin and if you have feedback of problems, please report them on our Microsoft Message Analyzer Forum.
To learn more about some of the concepts briefly described in this article, see the following topics in the Message Analyzer Operating Guide on TechNet:
Woohoo! Congrats folks.
And what sci-fi reference is "a new beginning"? I am hoping you don't mean www.imdb.com/.../tt0214641.
All we need is an easier way to deploy, execute and capture on remote workstations (inbuilt psexec functionality?) and we are set. Cheers.
Congrats folks, was so long waiting for you new methods of capturing and visualizing it! Perfect job. Will see you on making now the former "experts" perfect and customizable as well ;-) , Jan
Let's try it and see :)
New product and there is already Known issues documents :D
To see the PowerShell cmdlets run the PowerShell console as administrator. The module name is PEF.
PS C:\> Import-Module PEF
PS C:\> Update-Help -Module PEF -Verbose
PS C:\> Get-Command -Module PEF
Here is a link to the online help for New-PefTraceSession:
NedPyle: A beginning is a very delicate time...
This definitely looks like the Kwisatz Haderach...thanks for all the hard work. Can't wait to try it out.
Re: "execute and capture on remote workstations". Besides powershell, we also have a new remote capture feature that works with Windows 8.1 and Server 2012 R2. Stay tuned for more details once it's Windows 8.1 is official available.
In netmon, if I click "New Capture" followed by "Start", I can see a list of process names and PIDs in a tree on the left, which can then be drilled down to individual conversations within that process. Clicking on any node in the tree shows details of conversations in the "Frame Summary" window, and clicking on a line there gives more information in "Frame Details" and "Hex Details".
How do I accomplish the same thing in Message Analyzer?
The conversation tree and process tracking is something we still need to move forward to Message Analyzer from Network Monitor. We do grouping now, which creates an in-line conversation tree though it's not fixed anymore. Somebody in our forums asked a similar question (social.technet.microsoft.com/.../where-is-the-pidimage-name-info). Also the blog I point to might also be helpful.(blogs.technet.com/.../pivoting-on-trace-data-using-grouping.aspx)
Congrats on the release. Will netmon continue to be developed and updated or from this point on is it going to be message analyzer only?
Thanks Paul. For now I'll be sticking with Netmon but I look forward to Message Analyzer having that feature.
Is this in Server 2012 R2?
During installation I lost network connectivity. Reboots didn't help. Uninstalling it was the only solution that worked.
I'm running Windows 8 Pro with the Hyper-V role installed.