Stopping a Sniffer Trace Automatically When a Server Fails |
Q110619
"Stopping Sniffer Trace Automatically When an LM WS Fails"
It is difficult to capture network traces at the time of a server failure when there is nobody there to notice and stop the Sniffer.
The following is one possible method to automatically trigger a Sniffer on
server failure.
This method involves running a batch file on one machine that repeatedly
attempts to establish a connection to the server(s) in question. Upon
detecting a failure at the server, the batch file sends a broadcast message
(STOP THE SNIFF) to the domain, which the Sniffer triggers on.
The batch file:
rem USAGE: stopsnif [servername] [interval]
:start
net view \\%1
if ERRORLEVEL 1 goto bailout
delay %2
goto start
rem
rem The connection attempt failed. Stop the Sniffer!
:bailout
net send /d:davemacd STOP THE SNIFF
@echo
@echo Well, hopefully the Sniffer stopped!
Depending on the protocol, the text string "STOP THE SNIFF" may appear at
different offsets in your trace. It is therefore necessary to do the
following:
Additional query words: wfw wfwg prodnt
Keywords : kbnetwork
Issue type :
Technology : kbWinNTsearch kbWinNTWsearch kbwin2000AdvServSearch kbWinNTW310 kbWinNTSsearch kbWinNTS310 kbwin2000Ssearch kbwin2000Search kbWinNTS310xsearch kbWinNT310xSearch kbWinNTW310Search
|
Last Reviewed: December 7, 2000 © 2001 Microsoft Corporation. All rights reserved. Terms of Use. |