This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Working ona project where application users complains about the issue every night almost same time everyday. The issue reported only at night. To my wonder same application works fine and no complaint during night. We disablled all nightly batch to drill down if this might be causing due to nightly batch. However, this is nt the case.

Colllected some network related elements which I need your help on. Can some one help me with this.

I could see lot os [TCP Keep Alive] and [TCP Keep-Alive ACK] on the wireshark pane. How can I come drill down to an issue? I just have screenshots for those and I do ot find option to attach ythose screenshots here.

Some previous similar experiences may be helpful. We are on Solaris.

R, Kiddle.

asked 05 Aug '13, 01:46

kiddle's gravatar image

kiddle
1111
accept rate: 0%


The Keepalive probes are not causing any performance problem, they just indicate that a long living connection is idle. So a good start is probably to remove those using

!tcp.analysis.keep_alive and !tcp.analysis.keep_alive_ack

and 'Export specified packets'. Then you might want to remove (most of) the data portion by running

editcap -2 100 infile outfile

and share it on www.cloudshark.org for others to give it a try...

permanent link

answered 05 Aug '13, 05:08

mrEEde's gravatar image

mrEEde
3.9k152270
accept rate: 20%

edited 05 Aug '13, 05:08

where application users complains about the issue every night almost same time everyday. The issue reported only at night.

Please check if there are another applications that utilize (overload) the network during the night. I mean not only batch jobs on your system, but also large backup or data sync jobs (as you said: every night at the same time !!), that run over the network and put high load on switches, routers, firewalls, etc.. That often causes the kind of problems you describe.

However, without any further information (about the nature of the application, the involved systems, the involved network infrastructure, a capture file, etc.), it is hard to give any good advice.

Regards
Kurt

permanent link

answered 08 Aug '13, 07:35

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×752
×139
×7
×1

question asked: 05 Aug '13, 01:46

question was seen: 1,889 times

last updated: 08 Aug '13, 07:35

p​o​w​e​r​e​d by O​S​Q​A