Troubleshooting traffic capture on the Collector Home page


You view the Collector status on the Real User Collector Home page.

Collector status

Collector_Status.png

Use the Collector status metrics to determine the success of traffic capture and to diagnose possible causes of failure. A hit consists of the HTTP request and response pair.

Collector status metrics

Statistic

Description

Possible causes of traffic capture failure or suggestions for remediation

Traffic capture rate

Rate (hits per second) of HTTP and decrypted HTTPS traffic that was successfully processed by the Collector

 

None

Excluded traffic rate

Rate (hits per second) of traffic that was excluded due to the traffic inclusion/exclusion policies configuration

Check your configuration. Clicking the Settings hyperlink will take you to the Administration > Data flow settings > Traffic inclusion/exclusion policies page.

Sampling rate

Rate (hits per second) of HTTP requests that one or more Analyzers feeding this Collector could not process (for a number of reasons)

You can increase system resources to the Analyzer or have it process less traffic.

Packet loss

Number of TCP packets per 5-minute period that the Collector was unable to process

Possible causes of packet loss are as follows:

  • The Collector could not process the raw traffic data being copied to it because of resource limitations. You can try to increase resources on the Collector or filter out the non-HTTP and non-HTTPS traffic that is copied to the Collector. In this way, the Collector spends less time on discarding other traffic from other protocols. 
  • There are missing TCP packets based on their sequence numbers. If the Collector sees a TCP packet with sequence number 44, then it expects to see another TCP packet with sequence number 45 shortly thereafter. When this does not happen, the Collector ignores that TCP conversation and reports a packet loss.

SSL decryption status

Percentage of SSL traffic the Collector was able to decrypt. This is configurable in the Administration > Security settings > Key management page.

None

Broken hits status

Collector can report broken traffic from the following sources:

  • SSL traffic that was not decrypted
  • Incomplete HTTP transactions due to possible network packet loss on the infrastructure
  • TCP sessions that contain no HTTP or HTTPS payload

More than 20 possible causes exist for this status. You can obtain additional details about the source of broken hits from the trafficstatus CLI command. Open a BMC Customer Support ticket to assist you in understanding this statistic.

Contributed by @Baophac Do

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*

BMC TrueSight App Visibility Manager 10.5