Network capture tool that works on events

Event Log Driven Network Capture Tool:
http://nm3eventcap.codeplex.com/

Download and copy the tool to the terminal server.


Install network monitor on the terminal server.
http://www.microsoft.com/downloads/details.aspx?FamilyID=983b941d-06cb-4658-b7f6-3088333d062f&displaylang=en

Download and copy the nm3eventcap.exe to the server.
http://www.codeplex.com/NM3EventCap

Open a command window with run as administrator, run command,
Nm3eventcap.exe 56.cap –o 56 –f “tcp.port==3389″ –b 1000


NOTE: above command will keep capturing the logs until event 56 appears and the maximum log file size is 1G. Please keep it running and please do not close the command window and log off the session until the event 56 happens again.
(note that was in a partner post about TS debugging but it’s a great tip for debugging something in the event logs in general)


http://social.microsoft.com/Forums/en-US/partnerwinserver7rcthreads/thread/c8face23-348a-45b5-ae8b-1152e8f10ff9

Comments are closed.

Post Navigation