5.8

Table Of Contents
Capture Traffic with Wireshark/Ethereal
Start the capture of network traffic in Wireshark/Ethereal.
Procedure
1. From the Wireshark/Ethereal tool bar, click Capture > Start.
2. In the Capture Options, click Capture Filter.
3. Select csi.
4. Click OK.
Wireshark/Ethereal Capture Results
Messages that flow in and out of the Agent port (26542) appear in the Wireshark/Ethereal display. A single
inspection might show all of these results.
The message sizes indicated are current as of VCM Linux or UNIX Agent build 1.0.0.1270.
Sequence Color Description Content Length (approximate)
1 Green Ping n/a
2 Blue Ping result 164 bytes
3 Red Session Negotiation 2,222 bytes
4 Blue Negotiation Complete 3,538 bytes
5 Red Inspection Request Varies based on number of data
classes selected and if replication
is occurring. For example, a full
collection of Machine.General
with full data model replication
has a Content-Length of 71,934
bytes.
6 Blue Request Scheduled 8,386 bytes
7 (one or
more of
this set)
Red Session Negotiation 2,222 bytes
Blue Negotiation Complete 3,538 bytes
Red Check Status 2,618 bytes
Blue Current Status Varies depending on the status of
the request. For example, if the
request is still in progress,
Content-Length is usually 9,110
bytes, but when the request is
finished, Content-Length is
8,330 bytes.
8 Red Session Negotiation 2,222 bytes
9 Blue Negotiation Complete 3,538 bytes
Table 71. Wireshark/Ethereal Capture Results
VCM UNIX Agent
VMware, Inc.
79