Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
zsfsdgdsfs
Table of Content
CAPTURING........................................................................................................ 2
NETWORK CONNECTIONS ARE RESET WHEN MESSAGE ANALYZER IS INSTALLED......................................2
WHY CANT I VIEW WEB TRAFFIC ANYMORE? WHY IS IE NOW NOT WORKING THE SAME?.........................2
CAN'T START CAPTURING OR NO DATA BEING RECEIVED....................................................................2
IT SEEMS LIKE SOME OF THE MESSAGES ARE MISSING WHEN I CAPTURE...............................................2
I RECEIVE THE ERROR FAILED TO START ONE OR MORE TRACE SESSION(S) DUE TO THE FOLLOWING
MICROSOFT MESSAGE
ANALYZER
Frequently Asked Questions and Known
Issues
ERROR(S)
............................................................................................................................. 2
LIVE CONSUMER XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX FAILS TO START. ....................................2
UNABLE TO START FILTER INFO PROVIDER SERVICE.........................................................................2
POWERSHELL CAPTURE TRACE IS NOT SAVED TO PS EXECUTE PATH IF YOU ARE USING RELATIVE PATH........3
SIMULTANEOUS CAPTURES INVOLVING THE SAME PROVIDER MAY GIVE UNPREDICTABLE RESULTS.................3
THE WEB PROXY LIVE TRACE SCENARIO CAUSES ISSUES WITH INTERNET EXPLORER AND WINDOWS STORE
APPLICATIONS.......................................................................................................................... 3
INFORMATION DISCLOSURE ON WEBPROXY TRACE SCENARIO FOR MULTI USER SCENARIO........................4
HYPER-V TRAFFIC BETWEEN VIRTUAL MACHINES IS NOT CAPTURED IN WINDOWS SERVER 2008 R2..........4
REMOTE CAPTURE.............................................................................................. 4
SUPPORTED REMOTE CAPTURE SCENARIOS....................................................................................4
FAILED TO CREATE A REMOTE TRACE SESSION AFTER PROVIDING WRONG CREDENTIALS...........................5
ETW KEYWORDS IGNORED WHEN DOING REMOTE CAPTURE...............................................................5
FAILED TO CREATE A REMOTE TRACE SESSION OR TO CONFIGURE NDIS PROVIDER WHEN ENTERING AN
INVALID OR NOT REACHABLE HOSTNAME FOR LINK LAYER REMOTE CAPTURE..........................................5
WINDOWS 8.1 AND WINDOWS SERVER 2012 R2 SPECIFIC ISSUES.........................5
1 | Page
Known Issues
CANT.................................................................................................................................... 5
CAPTURE ON NDISCAP AFTER MESSAGE ANALYZER INSTALLATION.....................................................5
CAPTURE ON LOCAL LINK LAYER FAILS.......................................................................................... 5
UI...................................................................................................................... 5
CAN'T SEE COLUMNS FOR USB (OR OTHER) EVENTS.......................................................................5
CHARTS.................................................................................................................................. 6
ASSETS IN APPDATA/ROAMING ARE NOT UPDATED AFTER UNINSTALL/REINSTALL.....................................6
PERFORMANCE.................................................................................................. 6
SIZE OF TRACES THAT CAN BE LOADED/NUMBER OF MESSAGES THAT CAN BE CAPTURED........................6
ERRORS ON 32-BIT MACHINE...................................................................................................... 7
FILTERING.......................................................................................................... 7
IPV4 AND IPV6ADRESS FILTERS DO NOT WORK ON WIFI...................................................................7
FAST FILTERS ON WFP............................................................................................................. 7
SEQUENCE EXPRESSIONS...................................................................................7
WHAT
OPENING TRACES.............................................................................................10
MA IS UNABLE TO DECODE ETL FILE.......................................................................................... 10
SLOW PERFORMANCE LOADING CLUSTER LOG WITH TEXT LOG ADAPTER.............................................10
CLICKING MULTIPLE FILES FROM WINDOWS EXPLORER DOESNT DO ANYTHING.....................................10
Capturing
Network connections are reset when Message Analyzer is installed
Message Analyzer installs PEFNDIS driver in Windows 8/Windows Server 2012 and below
systems. When we add our driver on the system during the installation, the network stack
may reset. This might cause a temporary loss network access which can interfere with
programs that rely on a network connection. This problem is mitigated on Windows 8 and
Windows 2012 and above.
Why cant I view web traffic anymore? Why is IE now not working
the same?
Message Analyzer uses Fiddler to create a man-in-the-middle proxy to capture unencrypted
web traffic. When the Message Analyzer closes unexpectedly, Message Analyzer tries to
recover the original proxy settings; however, there are times when this may not occur. To fix
this issue, try restarting and then stopping a Web Proxy capture OR resetting your proxy
settings in the LAN settings section of the Connections Tab in Internet Options within
Internet Explorer.
2 | Page
Known Issues
The Web Proxy live trace scenario causes issues with Internet
Explorer and Windows Store applications
You might find that when you try to trace using the Web Proxy provider with Message
Analyzer that the application you are tracing fails to work or that Message Analyzer doesnt
capture any traffic.
3 | Page
Known Issues
This happens because Windows now protects client-to-client traffic by disabling local
loopback to 127.0.0.1 in certain conditions. This interferes with the way that Web Proxy
captures traffic.
Windows 8 has EPM (Enhanced Protected Mode) enabled default for the Windows 8 Internet
Explorer Application (the desktop version is not enabled). This mode includes the option to
block EMP. You can either remove this option, or change the Loopback exemption directly by
using the information below.
Windows 8.1 client and server have EPM enabled by default at this time for both versions of
IE.
Windows 8 and 8.1 have the loopback option disabled for all Windows Store applications. You
have to use workaround below to enable tracing for a specific Windows Store application.
Workaround(s) :
1. If the Web client is IE 10, then Enhanced Protected Mode has to be unchecked in the
advanced settings or on Windows 8 or later execute the command
"CheckNetIsolation.exe loopbackExempt -a -n=Windowsieac_001" to enable
the loopback exemption for IE.
2. On Windows 8 or later, if the Webclient is store app, then following command has to
be executed "CheckNetIsolation.exe loopbackExempt -a -n=<Appcontainer
name of the Web client application>" to enable the loopback exemption for
Windows Store applications.
Reference http://msdn.microsoft.com/en-us/library/windows/apps/Hh780593.aspx.
Capturing with the Web Proxy provider uses the Fiddler core API which has some known
limitations and issues:
4 | Page
Known Issues
Remote Capture
Supported Remote Capture Scenarios
Supported servers (remote capture target):
Special considerations:
If credentials are not provided, the current logged on users credentials (on the
client) are used for establishing connection to server.
When the client is domain-joined and the server is in workgroup, the remote
machine needs to be added to the trusted hosts list on the client by running the
following commands from an elevated command prompt:
5 | Page
Known Issues
UI
Can't see columns for USB (or other) Events
Some fields for providers can't be seen until they are loaded for the first time. USB and other
provider parsers are created dynamically the first time you open or start a new trace for that
provider. You can't see the provider fields in the Column chooser or use them for filtering
until the parser is created. Once the parser is created you can add fields as columns which
will be preserved, even if you reset the parser by removing it manually.
Charts
Cannot delete a data mapping
Data mappings for charts cannot be removed from the UI. You can edit the XML reference
which starts with <DataCollector> if you must remove the mapping. Export your assets from
the library management system, make a change and re-import the asset.
6 | Page
Known Issues
Performance
Size of Traces that can be loaded/Number of Messages that can
be captured
The number of messages that can be captured or the size of trace file that can be loaded is
dependent on the amount total memory (actual + virtual using paging file) on the machine.
Paging file settings can be adjusted using the Control Panel | System applet.
Another way to avoid dropped packets is to use Fast Filtering which will filter out messages
at the driver level. Fast Filtering can be configured for the specific providers that are being
used to capture.
Importing Time
When you load a non-native trace into Message Analyzer it will be imported (re/parsed).
The following are the approximate time it takes for importing:
.CAP files:
~2500 messages/second
~2 MB /second
.MATP files:
Though .matp files are already parsed and are native, you can reparse them if you use File |
Browse. You would do this if you wanted to combine a .matp with other traces so that they
can be viewed together as if they were one trace.
Opening a .matp using Quick Open,
double clicking in File Explorer, or dragging and dropping it into Message Analyzer is not an
import as the messages are already parsed, and will result in significantly faster loading
time.
~2000 messages/second
~1.5 MB /second
7 | Page
Known Issues
dynamically, until end of parsing. When large amount connections need to be parsed
simultaneously, the memory will be exhausted.
You need a machine with more memory to parse these traces, ideally 64 bits machine with
minimal 8G memory.
Filtering
IPv4 and IPv6Adress filters do not work on Wifi
IPv4 and IPv6 Link level fast filters don't work on WiFi on Windows 7 64bit. No traffic will
match these filters.
Sequence Expressions
What are the sequence expressions limitations?
in parameter for creating collection is not supported:
scenario S[out array<int> ids] = Request{ID in ids} interleave;
8 | Page
Known Issues
9 | Page
Known Issues
Opening Traces
MA is unable to decode ETL file
ETL traces can come in 3 different flavors, Manifest Based, WPP, and MOF. We can open and
parse manifest files if the manifest is on the machine (either registered or provided
10 | P a g e
Known Issues
manually) or if the manifest is embedded which happens automatically when you capture
with Message Analyzer. We currently don't support MOF file formats and for these the
messages will show up as ETW events.
11 | P a g e
Known Issues