Windows 7以é*1ã®netsh traceã³ãã³ãã使ãã¨Windowsã®æ¨æºæ©è½ã ãã§ãã±ããããã£ããã£ã§ããã®ã§ãããæ¹ãã¡ã¢ã
使ç¨ããã³ãã³ãããã³ããã¯ç®¡çè ã¨ãã¦å®è¡ããã
- ãã£ããã£éå§
- netsh trace start capture=yes traceFile=<ãã£ããã£ãã¡ã¤ã«å>
- netsh trace start capture=yes traceFile=C:\packets.etl
- ãã£ããã£åæ¢
- netsh trace stop
- 代表çãªãã£ããã£ãã£ã«ã¿ã¼
- CaptureInterface=<ã¤ã³ã¿ã¼ãã§ã¼ã¹åã¾ã㯠GUID>
- CaptureInterface="ãã¼ã«ã« ã¨ãªã¢æ¥ç¶"
- netsh trace show interfaces ã§ã¤ã³ã¿ã¼ãã§ã¼ã¹ä¸è¦§è¡¨ç¤º
- Ethernet.Type=<ã¤ã¼ãµãããã®ç¨®é¡>
- Protocol=<ãããã³ã«>
- Protocol=TCP
- IPv4.Address=
- IPv4.Address=192.0.2.1
- IPv4.SourceAddress=<éä¿¡å IPv4ã¢ãã¬ã¹>
- IPv4.SourceAddress=192.0.2.1
- IPv4.DestinationAddress=<éä¿¡å IPv4ã¢ãã¬ã¹>
- IPv4.DestinationAddress=192.0.2.1
- æ¢å®å¤
- capture=no
- capturetype=physical
- report=no
- persistent=no
- maxSize=250
- fileMode=circular
- overwrite=yes
- correlation=yes
- perfMerge=yes
- traceFile=%LOCALAPPDATA%\Temp\NetTraces\NetTrace.etl
- providerFilter=no
- ãã«ã
- netsh trace start help
- netsh trace show capturefilterhelp
ãã¨ã¯Event Trace Log File (.etl)ãMicrosoft Message Analyzerã§è§£æããã°è¯ãã
- Microsoft Message Analyzerï¼www.microsoft.comï¼
ã¾ãEvent Trace Log File (.etl)ã¯Wiresharkã§éããªãã®ã§ãMicrosoft Message Analyzerã§Network Monitor Capture File (.cap)ã«å¤æããã°Wiresharkã§ãéããããã«ãªãã
ãã®ä»ãåèã«ãªããããªURLã¯ä¸è¨ã®éãã
- Windows 7 のネットワーク診断とトレースï¼technet.microsoft.comï¼
- Netsh Commands for Network Trace in Windows Server 2008 R2 and Windows 7ï¼technet.microsoft.comï¼
- netsh trace コマンドにてパケット キャプチャを開始、停止する際に NIC のリンクダウンが発生する場合があるï¼support.microsoft.comï¼
- Microsoft Message Analyzer Operating Guideï¼technet.microsoft.comï¼
ã¡ãªã¿ã«è©¦ãã¦ã¿ã¦äºæ³å¤ã ã£ãã®ã¯netsh traceã³ãã³ãã§ã¯Promiscuous Modeã«ãªããªããã¨ããªããªã®ã§ãPromiscuous Modeã§ãã£ããã£ãããå ´åã¯Wiresharkãªã©ã§ãã£ããã£ããå¿ è¦ãããã
é¢é£ã¨ã³ããª
*1:ãµã¼ãOSã ã¨Windows Server 2008 R2以é