January 15, 2000

Using History Samples for Trend Analysis in Sniffer Pro

The History Samples function of Sniffer Pro is a welcome addition to this relatively new Windows-based GUI. Earlier DOS-based versions of the Sniffer software could sample network statistics over long periods of time, but these monitoring functions were contained within a separate executable than the protocol analyzer. Because of these limitations, history statistics could not gather while data was captured.

In the Windows-based Sniffer Pro, history information can be gathered at the same time as any other Sniffer function. This allows the network analyst to gather history statistics while the network data is captured to disk. This is especially helpful if questionable statistics arise while analyzing the history statistics. Specific timeframes can be investigated further by examining the captured Sniffer trace.

This tutorial uses Network Associates' Sniffer Pro version 3.0, although most versions of Sniffer Pro are similar to the screen shots and explanations in this tutorial.

The History Samples function of Sniffer Pro is a welcome addition to this relatively new Windows-based GUI. Earlier DOS-based versions of the Sniffer software could sample network statistics over long periods of time, but these monitoring functions were contained within a separate executable than the protocol analyzer. Because of these limitations, history statistics could not gather while data was captured.

In the Windows-based Sniffer Pro, history information can be gathered at the same time as any other Sniffer function. This allows the network analyst to gather history statistics while the network data is captured to disk. This is especially helpful if questionable statistics arise while analyzing the history statistics. Specific timeframes can be investigated further by examining the captured Sniffer trace.

This tutorial uses Network Associates' Sniffer Pro version 3.0, although most versions of Sniffer Pro are similar to the screen shots and explanations in this tutorial.
The History Samples

The history samples function can be found on the main toolbar as a graph button,

history_button.gif (8194 bytes)

or from the Monitor pull-down menu.

history_menu.gif (13164 bytes)

The history samples window contains many statistics that can be gathered over time. These statistics differ from one topology to another. These are the default Ethernet history samples:

ethernet_history.gif (32910 bytes)

There are additional vertical toolbar buttons on the left side of the history samples window. Clicking the right mouse button on any history sample can also access these functions

start_sample_button.gif (1088 bytes) The top button starts the sample. This is only available when a history sample statistic is highlighted. Only one history sample statistic can be highlighted at a time.

The next four buttons determine the current view of the history samples window.

large_icons_button.gif (1059 bytes) The Large Icons button is the default view.

small_icons_button.gif (1068 bytes) The Small Icons button reduces the size of the icons, allowing more icons to reside in a window. This is especially helpful when working with WAN topologies, where there are over 100 history sample statistics from which to choose!

list_button.gif (1064 bytes) The List button places each history sample statistic in a columnar list.

details_button.gif (989 bytes) The Details button list each history sample statistic with it’s associated low threshold, high threshold, interval (in seconds), and sample period.

properties_button.gif (1053 bytes) The Properties button provides a method of changing the general history variables and the graph colors.

Creating Multiple History Samples

The Add Multiple History button allows the network analyst to gather multiple history statistics into a single graph. Only ten graphs can be active simultaneously in Sniffer Pro, so the multiple history function helps to increase the number of statistics that can be collected.

To create a graph with multiple history statistics, press the add_multiple_history_button.gif (1040 bytes)Add Multiple History button.

multiple_history_general_dialog.gif (21692 bytes)

In the Name field, choose a name for this graph. The Name field is limited to 20 characters.

The sample interval determines how often a graph will update statistics. The maximum number of samples per graph is 3,600. The default is fifteen seconds, which provides a sample period of fifteen hours. The minimum is one second, and the maximum is 3600 seconds (one hour). A broadcast and multicast analysis may require gathering statistics every second, which would limit the total sampling period to one hour.

The graph type of Bar, Area, or Line can be chosen as default in this dialog box, but can be changed any time during or after the sample period.

multiple_history_selection_dialog.gif (19753 bytes)

The Selection tab allows the network analyst to select the statistics for the graph. Statistics that have large values should be moved to the bottom of the list, since these appear behind the other statistics in the three-dimensional graph views.

multiple_history_color_dialog.gif (25119 bytes)

The Color tab allows the modification of colors for the foreground, background, and for each statistic.

Clicking ok_button.gif (1405 bytes) saves the new multiple statistic history sample to the list of default history samples.

Starting a History Sample

To start a history sample, double-click on the appropriate history sample icon. A graph will appear and the collection of statistics will begin.

history_graph.gif (24037 bytes)

While the graph is running, the toolbar buttons on the left side of the graph window can alter the graph properties.

The first three buttons change the graph type between bar_button.gif (984 bytes) bar, area_button.gif (992 bytes) area, and line_button.gif (1062 bytes) line.

The next group of four buttons changes the graph views.

log-linear_button.gif (1078 bytes) The logarithmic/linear button changes the scaling of the vertical axis, which is helpful for displaying a graph's information when the statistical values are close together.

2d-3d_button.gif (992 bytes) The 2D/3D button toggles the graph between a three-dimensional and two-dimensional view.

legend_button.gif (1071 bytes) The Legend button toggles a graph legend, which is helpful on multiple history graphs.

border_button.gif (1007 bytes) The border button draws a black border around the history samples.

pause_button.gif (1052 bytes) The Pause Screen Updates button can freeze the sample graph. While paused, history samples continue to gather. Pressing the pause button again will update the graph to the latest real-time view.


Exporting History Sample Information

The Export button export_button.gif (1074 bytes) provides a method to save all history information into an external file. This button prompts for a filename and an export format. Note that the history information is still gathered while the export dialog box is active. The exported information will consist of all information gathered before and during this period.

export_dialog.gif (11161 bytes)

The three export formats are Comma Separated Value (CSV), text with tab delimiters, and text with space delimiters. For most external programs, CSV format is the easiest and most common text format for the importing of information.

Saving History Samples

The history samples can be saved at any time. If the history samples have reached their maximum number of data points, the graph will stop gathering statistics.

To save the graph, make the graph the active window and choose the File pull-down menu and select Save. The Save dialog box automatically displays the Sniffer Pro History Files (*.hst) format.

save_history.gif (7319 bytes)

If the history graph is active, history statistics will continue to gather in the background. The saved history file will consist of all information gathered before and during this period.


Final Notes

The information gathered during a history sample can be used to pinpoint long-term network problems. However, the history sample display cannot show a large number of data points at one time. For more information on the use of the Sniffer Pro history capabilities, read the NetworkUptime.com tutorial, "Using Excel to Graph Sniffer Pro History Samples"

Posted by james_messer at January 15, 2000 08:06 PM



Comments
Post a comment

Thanks for signing in, . Now you can comment. (sign out)

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)


Remember me?