New Version #Microsoft Message Analyzer #skype4b #lync #azure #MMA #cloud #storage #SQOS #RNAS

 

Microsoft Message Analyzer (v1.3) is the current versioned tool for capturing, displaying, and analyzing protocol messaging traffic and other system messages. Message Analyzer also enables you to import, aggregate, and analyze data from log and trace files. It is the successor to Microsoft Network Monitor 3.4 and Message Analyzer v1.2. Message Analyzer is a key component in the Protocol Engineering Framework (PEF) that was created by Microsoft for the improvement of protocol design, development, documentation, testing, and support. With Message Analyzer, you can choose to capture data live or load archived message collections from multiple data sources simultaneously.
Message Analyzer enables you to display trace, log, and other message data in numerous data viewer formats, including a default tree grid view and other selectable graphical views that employ grids, charts, and timeline visualizer components which provide high-level data summaries and other statistics. It also enables you to configure your own custom data viewers. In addition, Message Analyzer is not only an effective tool for troubleshooting network issues, but for testing and verifying protocol implementations as well.

 

Microsoft Message Analyzer Operating Guide

http://blogs.technet.com/b/messageanalyzer/archive/2015/05/20/message-analyzer-1-3-has-released-build-7534.aspx

  • Updated Protocols: TCP, HTTP, LDAP, RDPBCGR, KerberosV5, MSRPCE, IMAP, RPCH, TLS, SSL, TDS, TSGU, SIP, LPR, NNTP, TURN, POP3, SMTP, MPA, FTP, iSCSI, NBTNS, NBTSS, SOCKS, SunRPC, SMB2, RSVD
  • New Windows 10 Protocols: SQOS, RNAS
  • Other New Protocols: CSSP, NetFlow, IPFIX, RDPEFS, RDPERP, RDPESC, SCMR

Fiddler .SAZ – Now you can open .SAZ files from Fiddler directly. Now correlate fiddler traffic with network traces, ETL’s and log files.

Viewpoint Improvements – Viewpoint has been separated as a separate tool, to centralize it’s functionality in one place, including the hiding of Operations. Now a View Filter before Viewpoints, so that you can drill down with a filter, change your Viewpoint, and still see all the data based on the high-level View Filter.  You can also apply a new Viewpoint Filter that is relative to the currently applied Viewpoint, which works like the previous view filter behavior.

GZIP decompression – Message Analyzer can now automatically decompress HTTP payloads that have been compressed using GZIP.

Decryption Improvements – Support for TLS decrypted protocols like RDP, TDS and LDAP. Also we’ve improved some of the error messages reported by the Decryption tool window.

Parser and Text Log Updates – New protocol parsers like SRVS, RDWR, WSH, EVEN, and many more. Updates to the Netlogon parser and the addition log file parsers for Lync, SCCM (System Center Configuration Manager), ULS (SharePoint), and VMM (Virtual Machine Manager) logs.

 

Message Analyzer can now retrieve data in new ways. Analyze them individually or combine them with other data as well:

  • SQL/Azure – Open SQL and Azure Tables and import that data to correlate against other information. Import Azure Blob data as well.
  • PowerShell – Execute a PowerShell command and retrieve the resulting data. For instance enter “dir” as a script, which maps to the Get-ChildItem cmdlet. This will show you the results in the Analysis Grid.
  • Event Logs – Directly open local or remote event logs in to a static session.

 

Go To Message (Ctrl+G) – Allows you to go to a message by entering a message number in the Go To Message dialog.   If you have a single data source loaded, the first message in that source that matches your entry will be found.  When there is more than one data source loaded you can select a specific data source in which to search for a message, or you can search across all sources.

 

Microsoft Message Analyzer Operating Guide

Microsoft Message Analyzer

 

Microsoft Message Analyzer Usage Scenario Guidance

The installation of #MMA is easy in just a few steps .

Microsoft Message Analyzer is a new tool for capturing, displaying, and analyzing protocol messaging traffic. It is the successor to Microsoft Network Monitor 3.x and is a key component in the Protocol Engineering Framework (PEF) that was created by Microsoft for the improvement of protocol design, development, documentation, testing, and support. With Message Analyzer, you can capture live data or retrieve archived message collections from saved files such as traces and logs. Message Analyzer also enables you to display data in a default tree grid view and in selectable graphical views that employ grids, charts, and timeline visualizer components that provide high-level data summaries and other statistics.

More info : Microsoft Message Analyzer Usage Scenario Guidance

clip_image002 clip_image004 clip_image006

clip_image008 clip_image010

After the installation no Reboot is required , ready to start.

 

clip_image012 clip_image014 clip_image016

The Welcome screen is nice and direct links to the blog or forum is there or other help pages

clip_image018 clip_image020 clip_image022

Sample filters SMB filters are there if you want to capture the traffic extra options can be set

clip_image024 clip_image026 clip_image028

 

Firewall options are all there

 

clip_image030[1]

clip_image032 clip_image034  imageimage

 

IntelliSense UI for filter creation – As one of the most requested features, Filter IntelliSense is now available for exploring protocol message hierarchies to find the fields you need to build filter expressions. The capabilities are vastly improved compared to Network Monitor, now displaying protocols, messages, fields, structures, properties, annotations and more!

MAIntellisenseBeta2

· Quick filter – Quick filtering makes it easy to create a time window in which to view trace results!   Unlike BSV, it filters messages in memory after loading them instead of during import.  Just select the traces you want, adjust the time slider as needed, and you are done.  It’s that easy.

MAQuickFilterBeta2

· Capture firewall discard events – This feature allows you to discover how the firewall is affecting network traffic.  New messages tell you when traffic is blocked and associated IDs point to the specific firewall rule responsible for dropping the message.

· OPN Viewer – You can right click on any field and select Go to Definition to view the field’s OPN definition.  This feature provides the equivalent functionality of the NPL Viewer in Network Monitor 3.4.

MAOPNViewerBeta2

· Parsing REST Protocols – This feature enables you to diagnose and analyze RESTful web services.  RESTful web services are one of the fastest growing network areas.

· Performance improvements:

o Message Analyzer startup time has improved by over 50%.

o Sorting on selected column has improved by 60%.

o Grouping has improved by 30%

o Parsing after the initial load has improved by up to 15%, depending upon the protocol type.

Message Analyzer also presents exciting graphic viewer features that are still under development, but we would like to share them with you now to get your initial feedback:

· Gantt viewer – Do you need to see a bird’s eye view of your message traffic?  Message Analyzer now includes a highly customizable Gantt Viewer that provides easy-to-use navigation, zooming, and the ability to drill down into further details, as necessary.

Microsoft Message Analyzer Usage Scenario Guidance

· Console viewer provides an interactive command-line interface for filtering, sorting, grouping, and viewing messages collections.

Microsoft Message Analyzer #MMA Microsoft Network Monitor

Message Analyzer Icon 48

Microsoft Message Analyzer

Meet the successor to Microsoft Network Monitor!

Microsoft Message Analyzer has been released to the public.

As you might guess from the name, Message Analyzer is much more than a network sniffer or packet tracing tool. Key capabilities include:

• Integrated "live" event and message capture at various system levels and endpoints

• Parsing and validation of protocol messages and sequences

• Automatic parsing of event messages described by ETW manifests

• Summarized grid display – top level is “operations”, (requests matched with responses)

• User controlled "on the fly" grouping by message attributes

• Ability to browse for logs of different types (.cap, .etl, .txt) and import them together

• Automatic re-assembly and ability to render payloads

• Ability to import text logs, parsing them into key element/value pairs

• Support for “Trace Scenarios” (one or more message providers, filters, and views)

(To capture at the NDIS and Firewall layers without running as admin, you must log off and back on after installation to pick up the necessary credentials. Please do this!)

Powerful, extensible viewing and analysis

image

•Browse, Select, View

•Browse for messages from various sources (live, or stored)

•Select a set of messages from those sources by characteristic(s)

•View messages in a provided viewer, configure or build your own

•A new high-level grid view

•High level “Operations” view with automatic re-assembly

•“Bubbling up” of errors in the stack to the top level

•Ability to drill down the stack to underlying messages and/or packets

•On the fly grouping, filtering, finding, or sorting by any message property

•Payload rendering

•Validation of message structures, behavior, and architecture

•Does the protocol comply with the specifications?

imageimage