3 ms·
I believe it was Message Analyzer, and what was super cool was its ability to correlate ETW stuff. So you could literally see the interplay between... say... a
by c0nsumer 3y ago
I believe it was Message Analyzer, and what was super cool was its ability to correlate ETW stuff. So you could literally see the interplay between... say... a webserver log, an OS level NIC driver log, and a network capture.
I still don't get why MS stopped its public distribution, although I do know it was pretty buggy as released...
And yeah, netmon is great. I still use it when I want to filer Windows captures on PID, since Wireshark won't do that. (Even though netsh or pktmon -- built in Windows tools for recording captures -- have it in the header...)
- muststopmyths 3y agoyou're right Message Analyzer. My mistake.