To view capture data, navigate to Files, select a capture, and run a Forensic search. Open Forensic Searches, where the most recent capture appears in the list. Select the capture you just created. The Overview section will appear on the left-hand side.
For more information about forensic searches, see Forensics view.
A capture can have the following views:
- Dashboards: These views display graphical data about your
network summarized into several easy-to-read dashboards.
- Network: This dashboard provides an overview of network statistics for the capture. See Network dashboard.
- Applications: This dashboard provides key statistics for applications in the capture window. See Applications dashboard.
- Voice & Video: This dashboard provides a visual display of several VoIP-related statistics for the capture window. See Voice & Video dashboard.
- Compass: This dashboard lets you view network utilization, and top statistics from a real-time capture occurring on a network analyzer, from a single supported capture file, or from multiple capture files. See Compass dashboard.
- Capture: These views display information about packets
captured into the capture buffer.
- Packets: This view lists all of the packets placed in the buffer of a capture window (or capture file). The Decode and Hex panes show the contents of the selected packet decoded or in hexadecimal and ASCII. See Packets view.
- Events: This view collects messages generated by events relating to the particular capture window. These events include the results of notifications generated by the triggers or analysis modules selected for the capture window. See Events view.
- Expert: These views provide expert analysis of delay,
throughput, and a wide variety of network events in a conversation-centered view of
traffic in a capture window.
- Clients/Servers: This view makes it easy to track events and to see them in the context of peer-to- peer or client-server traffic patterns. See Expert Clients/Servers view.
- Flows: This view displays each flow independently in a flat view. This simplified view allows you to compare flows to one another, regardless of the node pair to which they belong. See Expert Flows view.
- Application: This view allows you to categorize each flow by application. This view allows you to see who is using each application on your network and how each application is performing. See Expert Applications view.
- Event summary: This view provides an overview of detected network events across different layers. This allows you to identify performance issues and traffic patterns. See Event summary view.
- Event log: This view displays a detailed list of individual events, allowing you to quickly analyze specific network issues. See Event log view.
- Web: These views let you display web page requests and
responses, allowing you to track client/server activity within a capture. The same
web data is presented in four formats.
- Servers: This view lets you focus on which servers are being used. See Web view.
- Clients: This view lets you focus on which clients are using which servers. See Web view.
- Pages: This view displays a list of web pages with each individual request nested underneath. See Web view.
- Requests: This view displays a flat list of individual HTTP requests. See Web view..
- Voice & Video: These views let you display the voice and
video data in the following formats:
- Calls: This view displays one row for each call. See Calls view.
- Media: This view displays one row for each media flow. See Media view.
- Visuals: These views graphically display network traffic and
statistics.
- Peer Map: This view lets you visualize network traffic by displaying nodes and the traffic between the nodes. The lines indicate traffic between two nodes. The relative thickness of the lines indicate the volume of traffic occurring. See Peer map.
- Graphs: This view displays graphs of individual items from the other statistics views in real time. The data from these graphs can also be saved as tab-delimited or comma-delimited text, or as XML\HTML. This view must be enabled in the Graphs options of the Capture Options.
- Reconstructions: This view displays files extracted from reassembled HTTP payloads of capture files opened in LiveWire. This view lets you quickly see the files that are being transmitted across your network.
- Statistics: These views display various statistical data
about your network.
- Summary: This view lets you view key network statistics in real time and save those statistics for later comparison. Summary statistics are also extremely valuable in comparing the performance of two different networks or network segments. See Summary view.
- Nodes: This view displays real-time data organized by network node. You can choose to display the nodes in a nested hierarchical view (logical addresses nested beneath their physical address), or in a variety of flat tabular views. Right-click the column header to add or remove various columns. See Nodes view.
- Protocols: This view displays network traffic volume as a percentage of total bytes, broken down by protocol and subprotocol. You can choose to display the protocols in either a nested Clients/Servers view or a Flows view. See Protocols view.
- Applications: This view lets you view basic statistics about applications for a capture window. See Applications view.
- Countries: This view lets you view a geographical breakdown of traffic based on IP address for a capture window. See Countries view.
- MPLS/VLAN/VXLAN: This view lets you view statistics for MPLS, VLAN, and VXLAN networks. See MPLS/VLAN/VXLAN view).
- Wireless: These views display information about your wireless
network.
- Wireless: This view displays an SSID (Service Set Identifier) tree view of wireless nodes. See Wireless.