Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The...

24
The Industry’s Most Penetrating Packet Analysis Platform Reconstruct, Measure, Completely Characterize Multi-Tier High Capacity PCAP Analytics

Transcript of Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The...

Page 1: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

The Industry’s Most Penetrating Packet Analysis Platform

Reconstruct, Measure, Completely Characterize

Multi-Tier High Capacity PCAP Analytics

Page 2: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

NetData will allow you to: • Fully parses all the Application messages

• Carries extensive state information including SQL statements with the thousands of cursors established in each database session

• Associate the database transactions with particular user transactions

• Combine all aspects of a multi-tiered application

• Pinpoint exactly where in the application chain a problem occurred

• Analyze Information that is garnered simply from PCAP files.

• No system agent is needed

• Model different network conditions to determine how latency and bandwidth might affect end user performance.

NetData has the most comprehensive TCP analytics in the industry

NetData is a tool that reconstructs, measures fully characterizes all transactions,

including requests without responses.

NetData’s RAPID PERFORMANCE RESOLUTION Benefits

Page 3: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

What makes NetData Different?

Multi-Tier PCAP time synchronized analysis

PCAP PCAP PCAP

PCAP PCAP

PCAP

NetData DIFFERENTIATION

NetData

Page 4: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

Multi-Tier Transaction Analysis (The Holy Grail)

• Ability to time synchronize multiple PCAP trace files providing a Stateful PCAP analysis

• Stateful SQL Analysis

• Stateful Voice Protocol Transaction Analysis

Also

• 50x combined file size capacity of Wireshark

• Capability to Model Queues and Packet Shaping

• Network Modeling

• Unequaled number of application decodes

• TCP Sequence Gap Detection

• L7 Message Sequence Gap Detection (e.g. MQTT, FIX)

NetData DIFFERENTIATION

Page 5: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

• Analyze and diagnose every abnormal slowdown or failure, to improve performance and availability.

• Visualize system operation and understand where transaction time is spent.

• See the effect of flow-control and congestion-avoidance mechanisms on data-transfer speeds.

• See the effect of network latency (loop-delay) on response times.

• Diagnose critical problems quickly to minimize impact on business.

• Locate and characterize bottlenecks.

• Characterize transactions for capacity planning and feedback to developers.

• Analysis database performance; check for table blocking; identify candidate procedures for tuning.

• Check system health prior to load testing, regularly in production, and when any significant change is made to application or infrastructure – see and fix problems before they become serious.

• Besides reducing the risk to client productivity and business, applying these techniques sooner and resolving problems quickly shortens project times by days, weeks, or in some cases months resulting substantial savings in project costs

NetData RAPID PERFORMANCE RESOLUTION BENEFITS

Page 6: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

MODELING QUEUES AND PACKET SHAPING

Packet loss usually has a severe effect on data flow because congestion-avoidance scheme mandate an immediate reduction in the flow rate and cautious attempts to increase the subsequent rate. In modern networks most packet losses are caused by some form of buffer shortage – perhaps by an inability to marshal buffers in time, but more likely by a unique overflow or traffic regulator known as a packet shaper, with contracted Committed and Peak information rates.

NetData has extensive facilities to measure flow rates and also is able to determine the parameters that control packet queues, packet shapers and packet policers. It does this by modelling the behavior of packet queues, tokens buckets, leaky buckets and over overlaying performance on charts of measured performance.

Causes of Packet Loss - Modeling Queues and Packet Shaping

Page 7: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

MODELING QUEUES AND PACKET SHAPING

A file transfer was disrupted by frequent packet losses, indicated here by the selective –ack information and

the red packet strips plotted on the sliding window. The TCP fast-recovery scheme prompted retransmissions

with minimal delay but the bytes-in-flight area graph below the sliding wing shows that the congestion-

avoidance window was halved many times, severely reducing the data flow. Why were packets lost?

Page 8: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

MODELING QUEUES AND PACKET SHAPING

On the assumption that packets were overflowing a queue waiting for transmission over a 100 Mbps link. NetData modeled

the behavior of the queue with packets arriving and being dropped as indicated by the captured traffic. The cream area

representing graph queue length shows that packets were dropped (indicated by red squares) only when the queues size

reached 25 Kbytes. The model’s validity is confirmed by the markers for observed round-trip times which increase by

amounts which closely follow the modelled queue-waiting times (indicated by green circles). A subsequent examination of the

network path revealed an old router with only 25 KB of buffer space.

Page 9: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

SAP – USERS COMPLAINING ABOUT SLOW PERFORMANCE

Page 10: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

SAP – LIST OF ALL SAP TRANSACTIONS FROM A USER OVER 30 MINUTES PERIOD

Page 11: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

SAP – TRANSACTIONS ARE PLOTTED BASED ON HOW MUCH TIME THEY TOOK TO COMPLETE

ONE SOAP POST STATEMENT TOOK 10.5 SECONDS TO COMPLETE

Page 12: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

SAP ANALYSIS OF THE FRONT END AND BACKEND TRANSACTIONS

THIS SQL QUERY TOOK 10.3 OUT OF THE TOTAL 10.5 SECONDS: DBA NEEDS TO REWRITE THE QUERY

Complete listing of the query including all of the conditional clauses make it easy for a DBA to see the

mistakes.

SAP – ANALYSIS OF FRONT END AND BACK END TRANSACTIONS

This SQL query took 10.3 out of the total 10.5 seconds: DBA needs to rewrite the query

Page 13: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

TCP CHARACTERIZATION

Page 14: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

PACKET BY PACKET THROUGHPUT & LATENCY IMPACT

Page 15: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

TRANSACTION TIMING

Page 16: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

TRANSACTION TIMING

Page 17: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

PACKET TIMING

Page 18: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

TCP CHARACTERIZATION

Page 19: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

Most VoIP monitoring solutions will tell you the following:

• That there is indeed an issue.

• When the problem occurred.

• Call quality, Jitter, packet loss etc.

What they don’t tell you is….

• WHY

• Where

• How

NetData is all inclusive

VoIP

Page 20: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

VoIP PACKET TIMING

Page 21: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

VoIP RELATIVE TRANSIT TIME & THROUGHPUT

Page 22: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

NETDATA AS A SERVICE

NetData is provided only as a subscription that licenses its use by a single, designated user for a specified period.

A subscription provides: • Access to the latest version with new decoders & analytical tools as developed • Unlimited phone or email support on NetData’s operation • NetData may be run on only one primary workstation at a time (per licensed). • NetData will fix any fault that causes a crash when processing a capture file or produce incorrect

statistics, provided Measure IT receives a copy of the problem data file • Measure IT is unable to guarantee correct interpretation of all packet contents because the

specifications of many application protocols are proprietary and unpublished. Nevertheless, Measure IT is keen to broaden and improve NetData’s repertoire and will endeavor to improve application decoding when faults are recognized

NetData AS A SERVICE

Page 23: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

NetData Green Named User License Contact Us • Unlimited Web meetings and support • Access to User Forum and online videos

NetData Blue Contact Us • Access to User Forum and online videos • 5 pack x 1hour Web Meetings Contact Us

Site License also available Negotiated based on scope Training Negotiated based on scope

PRICING

Page 24: Multi-Tier High Capacity PCAP Analytics · • 50x combined file size capacity of Wireshark ... The model’s validity is confirmed by the markers for observed round-trip times which

CONTACT INFORMATION

http://cloudfectiv.com

IoT Enablement, IT Infrastructure Transformation and Analytics & BI Enablement Email: [email protected] Phone: 888-206-6120