Information about Network Monitor 3
| Article ID | : | 933741 |
| Last Review | : | March 17, 2008 |
| Revision | : | 3.0 |
INTRODUCTION
This article contains download and support information, installation notes, and general usage information about Network Monitor 3. Network Monitor 3.1 is the latest version.
MORE INFORMATION
| • | Script-based parser model |
| • | Simultaneous capture sessions |
| • | Support for Windows Vista |
| • | Support for 32-bit platforms and for 64-bit platforms |
| • | Support for network conversations |
Download and support information
To download Network Monitor 3.1 visit the following Microsoft Web sites:
http://download.microsoft.com/download/1/8/f/18fd3dfa-ea78-4ed0-a62d-f5b043391ea4/NM31_Release_x86.msi (http://download.microsoft.com/download/1/8/f/18fd3dfa-ea78-4ed0-a62d-f5b043391ea4/nm31_release_x86.msi)
http://download.microsoft.com/download/1/8/f/18fd3dfa-ea78-4ed0-a62d-f5b043391ea4/NM31_Release_x64.msi (http://download.microsoft.com/download/1/8/f/18fd3dfa-ea78-4ed0-a62d-f5b043391ea4/nm31_release_x64.msi)
Support information for Network Monitor 3 is located at the following Microsoft Connect Web site:
You must sign in to the Web site by using a Windows Live ID. After you sign in, you can apply to participate in the program. To do this, in the Options column of the table, click Apply next to Network Monitor 3. After you enroll in the program, you have access to newsgroups, and you can submit bug reports.
Installation notes
Network Monitor 3.1 can co-exist with earlier versions of Network Monitor. By default, Network Monitor 3.1 is installed in the %Program Files% Microsoft Network Monitor 3.0 folder. Therefore, conflicts do not occur if an earlier version is installed in a different folder on the computer. When you install Network Monitor 3.1, Network Monitor 3 is uninstalled.
Network Monitor 3.1 includes a new driver for Windows Vista-based computers. This new driver supports new features of the Network Driver Interface Specification (NDIS) 6.0 driver. If you are using tools that rely on Network Monitor 2.x NPPTools, the tools will no longer work. To capture network data in Windows Vista, you must use Network Monitor 3.1. Network Monitor 2.x does not capture network data correctly in Windows Vista.
Suggested hardware to run Network Monitor 3.1 is listed as follows:
| • | 1 GHz or faster processor |
| • | 1 GB or more memory |
| • | 25 MB free space on the hard disk, and additional hard disk space to store capture files |
Network Monitor 3.1 is supported on the following operating systems:
| • | Windows Vista |
| • | Microsoft Windows XP |
| • | Microsoft Windows Server 2003 |
Warnings and cautions
Currently, we do not recommend that you run Network Monitor 3 on production systems. In scenarios where load is something to consider, use the command-line version of Network Monitor 3 to capture network data. The command-line version is Nmcap.exe. For more information about Nmcap.exe, see the Nmcap.exe command-line tool section.
Network Monitor 3 may consume lots of system resources. Some things to consider are listed as follows.
| • | Disk space
When you start a capture session, Network Monitor 3 stores frames in a sequence of capture files that are located in the Temp folder. By default, the size of each capture file is 20 MB. By default, if you do not stop the capture session, Network Monitor 3 continues to store capture files in the Temp folder until the free hard disk space on the computer is less than 2 percent. Then, Network Monitor 3 stops the capture session. You can configure the capture file size, the location where the capture files are stored, the free hard disk space limit, and other capture options. To do this, on the Tools menu, point to Options, and then click the Capture tab. |
| • | Memory use
In addition to capturing data, Network Monitor 3 assigns properties to frames, and then uses the properties to group the frames into conversations. Network Monitor 3 displays the conversations and the associated frames in a tree structure in the Network Conversations pane. The Conversations feature of Network Monitor 3 significantly increases memory use. This may cause the computer to become unresponsive. By default, the Conversations feature is turned off. Some higher-level protocol filters require conversation properties. To turn on the Conversations feature, click the Start Page tab, and then click to select the Enable Conversations check box. |
| • | Processor utilization
The Conversations feature of Network Monitor 3 may significantly increase processor utilization when lots of frames are processed. By default, the Conversations feature is turned off, as mentioned in the Memory use section. |
General usage
General usage information for Network Monitor 3 is listed as follows.
| • | Capture network data
As mentioned earlier, Network Monitor 3 may consume lots of system resources. Therefore, if you want to minimize the effect on system resources that may occur when you use Network Monitor 3 to capture data, use the Nmcap.exe command-line tool to capture data. Network Monitor 3 enables you to collect network data and to view the network data in real time as the data is captured. To start a capture session in Network Monitor 3, click the Start Page tab, click Create a new capture tab, and then either click the Start Capture button, or press F10. |
||||||
| • | Filters
Network Monitor 3 uses a simple syntax that is expression-based to filter frames. All frames that match the expression are displayed to the user. For more information about filters, do any of the following:
|
||||||
| • | Conversations
By default, the Conversations feature is turned off. This is the default setting because the Conversations feature can consume lots of memory, especially in scenarios when you capture data for long periods of time. To turn on the Conversations feature, click the Start Page tab, and then click to select the Enable Conversations check box. When you turn on the Conversations feature, frames are grouped and displayed in the Network Conversations pane in a tree structure according to the conversations to which they belong. For example, TCP data that uses the same source port and the same destination port is organized into a group. When you click a node in the Network Conversations pane, the corresponding conversation filter is automatically applied to the frames in the Frame Summary pane. Only frames that belong to that particular conversation are displayed. |
||||||
| • | Nmcap.exe command-line tool
The Nmcap.exe command-line tool enables you to configure when you want to start a capture session or to stop a capture session. You can also use the Nmcap.exe command-line tool to created chained captures. Chained captures enable you to create multiple capture files. However, the size of the capture files remains small. |
||||||
| • | Network Parsing Language (NPL)
Network Monitor 3 parsers are written in a language specifically to make parser development more straightforward. This also provides a level of protection against potential exploitation from malicious code that may occur if parsers were created as DLL files. NPL provides access to parsers. You can view or modify the parsers that are included in Network Monitor 3. |
Common issues
Common issues include the following:
| • | Protocols may not parse correctly. This issue may occur if either of the following conditions is true:
|
||||
| • | You receive one of the following error messages when you run Network Monitor 3 on a Windows Vista-based computer:
None of the network adapters are bound to the Netmon driver
This network adapter is not configured to capture with Network Monitor
This issue occurs if either of the following conditions is true:
For more information, see the Network Monitor 3 releases notes or see the Operating on Windows Vista topic in Network Monitor 3 Help. |
REFERENCES
APPLIES TO
| • | Windows Vista Ultimate |
| • | Windows Vista Enterprise |
| • | Windows Vista Ultimate 64-bit Edition |
| • | Windows Vista Enterprise 64-bit Edition |
Keywords:Â |
kbhowto kbinfo kbexpertiseinter KB933741 |
Microsoft Knowledge Base Article
This article contents is Microsoft Copyrighted material.
Microsoft Corporation. All rights reserved. Terms of Use | Trademarks
You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.
Back to the top
Leave a Reply