09.02.2014 Views

Windows sysinternals

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 13 Network and Communication Utilities 373<br />

FIGURE 13-4 Portmon port selection.<br />

The Result column shows the result of the request.<br />

Finally, the Other column shows additional relevant data about the request. For example, for<br />

a “set baud rate” IOCTL, Portmon shows the requested baud rate in the Other column. For<br />

read and write operations, Portmon displays the data length and then at least some of the<br />

data. By default, Portmon displays up to 64 bytes of data in ASCII form, using “.” to represent<br />

nonprintable characters. You can change the amount of data that is shown by choosing Max<br />

Output Bytes from the Options menu and setting a different number in the Max Bytes dialog<br />

box. You can also choose to show the data in hexadecimal form instead of ASCII by selecting<br />

Show Hex from the Options menu. Both of these options take effect on subsequently<br />

captured data. Portmon doesn’t change the display of data that has already been captured.<br />

Portmon monitors system memory usage and suspends its data capture if it detects that<br />

memory is running low, resuming capture only when the low-memory condition has eased.<br />

One way to limit Portmon’s own memory consumption is to set the History Depth to a nonzero<br />

value. This setting, on the Options menu, limits the number of events Portmon displays,<br />

discarding older events.<br />

You can increase the display space for output by selecting Hide Toolbar on the Options<br />

menu. You can also increase the number of visible rows by selecting a smaller font size.<br />

Choose Font from the Options menu to change the font.<br />

Unlike most Sysinternals utilities, which store their settings under HKCU\Software\<br />

Sysinternals, Portmon’s settings are stored in HKCU\Software\Systems Internals\Portmon,<br />

except the EulaAccepted flag, which is in HKCU\Software\Sysinternals\Portmon.<br />

Searching, Filtering, and Highlighting<br />

If you want to search for a line containing text of interest, press Ctrl+F to display the Find<br />

dialog box. If the text you specify matches text in the output window, Portmon selects the<br />

next matching line and turns off the Autoscroll feature to keep the line in the window. Press<br />

F3 to repeat a successful search.<br />

Another way to isolate output that you are interested in is to use Portmon’s filtering<br />

capability. Click the Filter button in the Portmon toolbar to display the Filter dialog box,<br />

shown in Figure 13-5. Filter and Highlight rules are automatically saved on exit and can be<br />

reapplied the next time you run Portmon.<br />

www.it-ebooks.info

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!