NETMON& Message Analyzer

NMCap /network * /capture  /file c:folder .chn:1MB 

NMCap /network * /capture (IPv4.SourceAddress == local ip address) and  (Ipv4.DestinationAddress == remote ip address) /file c:folderackup.cap:1MB

http://blogs.technet.com/b/askpfeplat/archive/2013/05/20/fire-amp-forget-how-to-stop-a-network-trace-programmatically-using-network-monitor.aspx
 http://blogs.technet.com/b/netmon/archive/2007/02/22/eventmon-stopping-a-capture-based-on-an-eventlog-event.aspx

http://blogs.technet.com/b/netmon/archive/2006/10/24/nmcap-the-easy-way-to-automate-capturing.aspx

http://blogs.technet.com/b/askpfeplat/archive/2015/08/03/diving-into-the-netlogon-parser-v3-5-for-message-analyzer.aspx

The effect of TCP Chimney offload on viewing network traffic

http://blogs.technet.com/b/networking/archive/2008/11/14/the-effect-of-tcp-chimney-offload-on-viewing-network-traffic.aspx

Information about the TCP Chimney Offload, Receive Side Scaling, and Network Direct Memory Access features in Windows Server 2008

http://support.microsoft.com/kb/951037

 http://www.symantec.com/business/support/index?page=content&id=TECH197934

http://www.cnblogs.com/awpatp/archive/2010/02/08/1666133.html

原文地址:https://www.cnblogs.com/WCFGROUP/p/3829328.html