Creating and running a new chain

Prev Next
To create and run a new chain:

Note

The stream is color-coded to indicate the direction of the data. You can filter the stream by direction and view the data in hex or ASCII format.

UI_Tools_Protocol_Encode_ShowAs.png
UI_Tools_Protocol_Encode_Selection.png
UI_Tools_Protocol_Encode_NewChain.png
UI_Tools_Protocol_Encode_Run.png
  1. Click Main_menu.png and from CONFIGURATION, select Search.

  2. Enter a query in the Query bar and click the search icon to perform a search.

  3. From the Event Table, click the checkbox next to one or more events you want to reconstruct.

  4. Click the Reconstruct button at the top of the Event Table. The NDR pivot engine processes the events and displays the results on the Packets tab.

  5. From the Packets tab, select an event from the Connections list to view all the packets associated with that event.

  6. Click the Stream Follow link that is associated with the event you selected to view the connection stream.

  7. From the Show data as menu, select Hex Dump.

  8. Click ENCODE/DECODE SELECTION to open the connection stream in the Payload Encode/Decode window Input section.

  9. Create a new chain by dragging and dropping the operations you want to run in the New Chain window.

  10. Click RUN to start the new chain and apply it to the entire connection stream. You can run the new chain against the entire connection stream or highlight a section of the connection stream you want to run the new chain against.