Filtering a packet trace in MainView IP


Use this procedure to filter the records displayed. You can select to display records for a date, range of dates, a port, IP address and protocol.

The packet trace view displays the first 37,500 packet trace records that match the filter criteria entered.

To filter a packet trace

  1. From the PKTTRACD panel position the cursor next to the column title Search Criteria, and press Enter.The Search Criteria expands displaying the Packet Trace filter fields (see the following table).

    Packet Trace Filter fields

    Field

    Description

    Start Date

    A specific date or the starting point of a range of dates to limit the records displayed based on the date of the packet.

    Start Time

    A specific time or the starting point of a range of times to limit the records displayed based on the time of the packet.

    Stop Date

    An ending date for a range of dates. Use this field with the Start Date field.

    Stop Time

    An ending time for a range of times. Use this field with the Start Time field.

    Port

    A port number to filter the packet trace based on source and destination port. The packet trace view displays any records that match either source or destination port.

    IP Address

    An IP address to filter the packet trace based on source and destination IP address. The packet trace view displays any records that match either source or destination IP address.

    Protocol

    A type of protocol such as TCP, UDP or ICMP.

    Max Records

    A number from 1-37,500 to define the maximum number of packet trace records to display. The default value is 37,500.

  2. Enter the filter criteria and press EnterThe packet trace view searches through all the trace records and displays the records that match the criteria entered up to the maximum number of records (Max Records) defined.

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*

MainView for IP 3.5