Network Monitor

  • TCP Analyzer Expert: Make Your Network Run Faster

    Performance problems suck...time! But years of "Where's Waldo" has trained our brains in preparation for this moment. The TCP Analyzer expert, available from our Experts Download Page[ http://go.microsoft.com/fwlink/?LinkID=133950] takes advantage...
  • Intro to Filtering with Network Monitor 3.0

    Challenges of Filtering One of the biggest changes between NM2.x and NM3.0 is the way you do filtering. Old NM2.x hacks may be challenged by the loss of the UI wizard to build filters. On the other hand, Ethereal users may be pleased and further encouraged...
  • Event Tracing for Windows and Network Monitor

    Event Tracing for Windows, (ETW), has been around for quite a while now as it was introduced in Windows 2000. It's basically instrumented logging that describes what a component is doing. Conceptually, it’s something like the proverbial printf("here1...
  • Parser Profiles in Network Monitor 3.4

    Parser Profiles are a new feature available in our 3.4 Beta . Rich parsers provide detailed information about every part of packet. However this detail comes with a price as it takes longer to parse and filter frames. Parser Profiles are designed to help...
  • Expert to Decrypt TLS/SSL Traffic

    One of the most popular requests we've had is to provide a way to view encrypted traffic. The new Decryption expert aims to solve this problem for TLS/SSL traffic. Using the Decryption Expert The purpose of encrypting data in the first place is to hide...
  • Message Analyzer has released!

    Thought I should mention here that Message Analyzer has released. Read the full story on our Message Analyzer blog .
  • Reducing Dropped Frames with Network Monitor 3.4

    by Darren J. Fisher – Network Monitor Development Lead Capturing network traffic is actually a very stressful task for most computers. With modern networks, traffic can arrive to a system at astounding rates. Most machines built these days have...
  • NMCap: the easy way to Automate Capturing

    OK, I'm not going to blow smoke up your Async port. I don't mean to say that the NMCap is necessarily easy to use, though it's not that hard. But any command line utility always has its quirks. Isn't that why GUI was invented? What NMCap does make...
  • Using High Performance Filtering

    There are certain scenarios where the High Performance Filtering feature added in Netmon 3.4 will provide the best performance for capturing with a filter. The idea is to filter frames before they hit the disk which can improve your performance by reducing...
  • Network Monitor 3.4 has Released!

    I’m proud to announce the release of Network Monitor 3.4 to the Microsoft Download center . We’ve included a bunch of new exciting features and updates. A new high performance capturing feature allows you to capture on faster networks without...
  • SMB Opportunistic Locking Behavior

    Behold the mysterious world of OpLocks (Opportunistic Locking). Often OpLocks will be disabled by a user or system administrator in order to help address a performance problem. And this practice might not always be the best course of action. Understanding...
  • Using Color Rules to Show Direction

    By Jin Feng Differentiating client requests and server responses can provide a clear-cut view and make it easier to understand what’s going on within a trace. Normally, with a flat trace this can be hard to determine and distinguish one packet from another...
  • Part 2: TCP Performance Expert and General Trouble Shooting

    Performance issues are one of the more difficult problems to trouble shoot. Without a baseline, it's often hard to determine if something is really slower. But TCP does contain some built-in behavioral patterns that can be used as a signal to tell you...
  • Message Analyzer Beta 2 has Released!

    Check out more information on the Message Analyzer release blog here .  Or go right straight to Connect and if you are registered you can download the beta. Enjoy!
  • Intro to the Network Monitor API

    I’ve recently played with a new tool here at MS, which analyzes HTTP traffic and provides performance information so that you can better tune your web servers and applications. I also have seen an internal SMB expert that summarizes SMB traffic, for instance...
  • Message Analyzer Beta has Released!!!

    Please read our post on our new Message Analyzer blog .
  • Capturing a Trace at Boot Up

    Capturing a trace during a boot is a common task that can be difficult to accomplish. In fact the most fool proof way to capture all traffic at boot is to capture the traffic from a 3rd party capturing machine in promiscuous mode. But this requires you...
  • Network Monitor 3.2 has arrived!

    I’m so excited about this release I had to commandeer Paul’s blog for the day and write about it. My name is Tawanda Sibanda and I am the lead program manager for Network Monitor. The team put a lot of effort into this version, adding many of the requests...
  • Reassembly Made Easier

    By using our latest 3.4.2455 release of the parsers and using a simple filter, you can now view reassembled traffic more easily for certain protocols. Normally when you reassemble a trace you see all the original frames plus the newly inserted reassembled...
  • Microsoft Protocol Test Suites Available

    We recently released a set of Microsoft Protocol Test Suites . OK it was a month ago, but we’ve been really busy…really! To access them you must have a Live ID and sign up. These Test Suites allow you to evaluate whether a protocol implementation meets...
  • Open Source Freedom for Network Monitor Experts

    We are excited to announce that we have moved 3 Network Monitor Expert projects and the Network Monitor SDK to the Outercurve Foundation . You can now contribute to: NMDecrypt – Decrypts SSL data, given the private key. NMTopUsers – Displays the top talkers...
  • Lex Thomas Talks about Troubleshooting with Network Monitor

    Lex Thomas is a Principal Technical Account Manager for the US Premier Support Services Team at Microsoft. He also provides Network Monitor training for premier accounts where he teaches the basics of network troubleshooting. In this three part video...
  • Filtering On Timestamps

    There are situations when you want to narrow a trace down to a certain time frame. However, creating a filter for a timestamp is not very straight forward. We will discuss how timestamps operate and ways to make filtering on timestamps workable. How Time...
  • NMTopProtocols Expert Released

    Michael A. Hawker is the Program Manager for Network Monitor. His focus has been on the API, UI, and Experts as they have been developed through versions 3.3 and 3.4. You’ve seen a lot of updates lately on Experts with the move to the Outercurve Foundation...
  • Understanding HTTP Flow with Netmon 3 - By Yuri Diogenes

    1. Introduction One of the most common protocols that we need to deal with these days is the HTTP Protocol. This is not only a privilege of Internet users, there are a lot of Intranet users that also use this protocol for internal transactions. ...