Home   |  Products   |  Download   |  Purchase   |  Support   |  Resources   |  Company   |  Contacts   |  Service   |  Forum
 
Support
Installation Layouts
FAQ
Glossary
Contact Support

 
Feedback
Pre-Sales Toll Free: 888-467-2634(USA)
 
HomeSupport > FAQ > Products FAQ
 
Products FAQ

Colasoft Capsa Colasoft MSN Monitor Colasoft EtherLook
     
Colasoft Capsa
This FAQ is about Colasoft Capsa, please contact us if you can not find the answer for your questions.
  1. What is Colasoft Capsa?
  2. What can I do with Colasoft Capsa?
  3. What are the differences between Colasoft Capsa Professional and Colasoft Capsa Enterprise?
  4. What is a filter?
  5. Can Colasoft Capsa analyze network traffic occupation?
  6. I have a small LAN which connects through a Linksys 24 port switch. I can see the web traffic on the machine that the software is on but cannot view the sites visited by the remainder of the computers on the LAN.
  7. I received a blue screen with CSTDI50.SYS (Colasoft TDI Loopback Driver), the screen said IRQ NOT LESS THAN OR EQUAL
  8. Our LAN is connected with a hub, but I can only detect my own traffic.
  9. I start capture and visit some https websites, but I don't get any log information.
  10. I would like to record just the web sites visited not every gif on the web site, can I do that?
  11. Does Colasoft Capsa enable me as a network administrator to easily see who is listening to the radio and downloading music online?
  12. After I entered the serial number and license key, they didn't work.
  13. Some of the Host Names are not being displayed properly. Do you have idea why it only gives us IP addresses and not find the computer names?
  14. Is there a way to keep an area of the graph on screen so I can save that section of the graph that is important to me?
  15. I am wondering if Colasoft Capsa has an IP logger on it or can it log all IP address and calculate the total bandwidth of each IP address?
  16. We have a 70 Suite offices and 1 T1 sharing, the T1 goes down some times because some customers create Internet traffic with viruses and the usage of the T1 exceeds the 100%, can Colasoft Capsa help us find who is causing these issues?
  17. Can I monitor the traffic of my remote business network?
  18. I'm on a LAN, when I run Colasoft Capsa and try to choose an adapter, the list does not show any adapters on my network.
  19. How can I use Colasoft Capsa to analyze traffic on other switch ports if our network is tied together with a switch?
  20. We use a Windows 2000 server and Exchange. We sent some emails but didn't see any information from Colasoft Capsa.
  21. Why all the packets I see in the Packets view have a bad checksum?
  22. Can I change adapter when Colasoft Capsa is running?
  23. When Colasoft Capsa runs it slowly accumulates more RAM until the system runs out of physical memory, I set the packets to purge completely when the buffer is 100%, this helps but does not resolve the issue. Please advise.
  24. I am using Colasoft Capsa 5.0 and would like to have an upgrade, can I share the packets with the new version?
  25. Why I can not see any information in the Logs view when I send/receive emails via http string?
  26. I cannot see any original content of an email by double-clicking it in the Email Messages list of Logs view. What can I do?
  27. Can I locate the machines infected by worms with Colasoft Capsa?
  28. Can I find out the reason of web slowdown with Colasoft Capsa?
  29. We configured IP address with DHCP in our network. How can I locate the trouble PC when we get network problem?
  30. We need to add Port 10081 at the end of URL address when access our firewall via Web Interface. Why I can not find any information in the Logs view of Colasoft Capsa?
  31. We got IP conflicts in our network recently. Does Colasoft Capsa can help me?
  32. Can I detect the BT download in our network with Colasoft Capsa?
  33. I need report files of the analysis, can Colasoft Capsa generate reports?
  34. There are HTTP Slow Response, FTP Slow Response, SMTP Slow Response and POP3 Slow Response in the diagnoses events when I run Colasoft Capsa. What's wrong and does it severe?
  35. What the means of "Other" belongs to TCP or UDP protocol in the Protocols view?
  36. Can I find out the resource with Colasoft Capsa if our server was attacked?
  37. Our LAN is connected with a switch, but I can only detect my own web traffic. Why?
  38. There are multiple IP addresses in a single NIC when I view the captured packets. Does it normal and why?
  39. There are various departments in our company and each of them belongs to a different VLAN. Can Colasoft Capsa analyze traffic of each department and how?
  40. I double clicked a protocol in the Protocols view but can not see the corresponding packets in the popup window.
  41. How can I get clear view of some nodes when there are too many nodes in the Matrix view?
  42. When I imported packet capture, the time displayed in "Graphs" view does not match the one in "Packets" view. Why?
What is Colasoft Capsa?
A: Colasoft Capsa is an expert network analyzer designed for monitoring and diagnosing network traffic flowing through local network, helping network administrators to detect and troubleshoot network problems. With the abilities of real time packet capture, accurate protocol analysis, automatic network events diagnosis, combined powerful filters and statistic information of global network, Colasoft Capsa let you quickly and efficiently fix the network troubles.
Top
What can I do with Colasoft Capsa?
A:

Network administrators
Diagnose network problems, detect the PC infected virus, monitor network traffic, analyze network protocol, detect network vulnerability.

Company administrators
View the accesses of http browse, ensure email security, against unauthorized access to the sever.

Security managers
Supervise the contents transmitted in network, analyze nonnormal traffic, network security complement.

Consultants
Analyze network troubleshoots, solve network problems for customers, optimize network capability.

Network application developers

Debug network applications, optimize program capability, test the content sent/received, examine network protocols.

Top
What are the differences between Colasoft Capsa Professional and Colasoft Capsa Enterprise?
A: Colasoft Capsa has two editions: professional edition and enterprise edition. The professional edition offers the necessary features of a great network monitoring tool at an inviting price, it can meet IT professionals' basic needs in network traffic monitoring and protocol analysis. The enterprise edition has many more advanced features than the professional edition, such as supports dial-up adapters, loopback packets on local host, statistic graphs and reports, network traffic matrix, advanced packets filters, simultaneously monitoring multiple adapters, etc.

Click here to view the comparison table.
Top
What is a filter?
A: In Colasoft Capsa, a filter is a rule or set of rules that separates captured data and performs a particular action based upon your instructions. The filters decrease the packets to be analyzed and displayed, enabling you to focus on what you are really interested in. Colasoft Capsa has two kinds of filters: global filters and project filters. Global filters are some commonly used protocols filters, which can be applied to the current project. Project filters are only applied to the current project.
Top
Can Colasoft Capsa analyze the traffic occupation in the network?
A: Colasoft Capsa provides users detailed statistics information of the whole network or a specific subnet, MAC/IP address or protocol, including total traffic, traffic each second, average traffic and etc, and shows these information in the Endpoints view and Protocols view.
Top
I have a small LAN which connects through a Linksys 24 port switch. I can see the web traffic on the machine that the software is on but cannot view the sites visited by the remainder of the computers on the LAN.
A: Please check your switch first, if it supports "port mirroring", when this feature enabled you will be able to monitor the entire LAN's traffic.

If it dose not support "port mirroring", you can install Colasoft Capsa on your Internet gateway (if applicable), or on a workstation which is connected to the same hub with your Internet gateway.

For the instructions on how to configure port mirroring, please refer to the document coming with your switch or contact the provider. Click here for a reference list of hardware that support port mirroring, some installation layouts can also be found at Colasoft.com.
Top
I received a blue screen with CSTDI50.SYS (Colasoft TDI Loopback Driver), the screen said IRQ NOT LESS THAN OR EQUAL.
A: A possible reason is the packet driver was installed improperly. Please run regedit.exe and delete the following keys:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CSTDIDRV

The keys also can be found in:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CSTDIDRV
or
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\CSTDIDRV

Then reinstall Colasoft Capsa.

Top
Our LAN is connected with a hub, but I can only detect my own traffic.
A: Generally, if a NIC supports promiscuous mode it can work well with Colasoft Capsa, a possible reason is your hub actually acts as a switch though labeled as a hub (e.g. Linksys hubs).

Another possible reason is you are using a multi-speed hub, in which case you can't see the traffic from the stations operating at the speed that is different from your NIC's speed (e.g. if you have a 10 Mbit NIC, you can't see the traffic generated by 100 Mbit NICs).

Top
I start capture and visit some https websites, but I don't get any log information.
A: The secure hypertext transfer protocol (HTTPS) is a communications protocol designed to transfer encrypted information between computers over the World Wide Web, currently no sniffer tools can reconstruct HTTPS packets to primary plain contents except the packet header; in other words, if you are visiting a https website you can not get the URL from Colasoft Capsa' web log, but associated connections information can be found in the "Connections" view.
Top
I would like to record just the web sites visited not every gif on the web site, can I do that?
A: Yes, with the flexible filters of Colasoft Capsa you can focus on the packets you are really interested in. Please follow the steps below to set a HTTP filter:
  • Click Log button on the toolbar to enter log setting page
  • Enable HTTP Log Conditions in the left list
  • Select Content Type in the Exceptions table, enter "images/jpg" in the box corresponding to it
  • Click OK to confirm your setting
Top
Does Colasoft Capsa enable me as a network administrator to easily see who is listening to the radio and downloading music online?
A: Yes. The standard ports for media protocols are:

RTSP - port 554
PNM - port 7070 (also known as PNA port)
MMS - port 1755

By setting port filters in the "Project Settings - Filter" dialog you can easily find out who is visiting media resources; to monitor the downloads of media files (e.g. .rm), you can set a URL filter for HTTP analysis in the "Project Settings - Advanced Analyzer" dialog.

Top
After I entered the serial number and license key, they didn't work.
A: Please copy and paste the serial number and licence key you received from us to the fields required, it may include unnecessary blank or input error if you type in the numbers.
Top
Some of the Host Names are not being displayed properly. Do you have idea why it only gives us IP addresses and not find the computer names?
A: Colasoft Capsa resolves IP addresses in the following sequences:
  • Checks the host file for a match address entry, e.g. C:\WINDOWS\system32\drivers\etc\hosts.
  • Sends a resolution request if a DNS server is configured.
  • Sends a NetBIOS adapter status request to the IP address being requested, and then parses the IP address to the computer name if it responds with a list of NetBIOS names registered for the adapter.
However, if the target host is behind a firewall or NAT, Colasoft Capsa can not get the NetBIOS response packets. In this case, you can try to open the port 137 on the target host 's firewall.
Top
Is there a way to keep an area of the graph on screen so I can save that section of the graph that is important to me?
A: Yes. To show graph history, click the "Pause" button from the toolbar to pause refreshing the view (just the display stops refreshing, the collection for graphic data still continues), then you can scroll to any section of the graph and save it as .bmp, .png and .emf file; when you click "Pause" again, the "Graph" view will resume to show the latest statistic data.
Top
I am wondering if Colasoft Capsa can calculate the network bandwidth?
A: Yes. The network bandwidth concludes interior bandwidth and exterior bandwidth. Colasoft Capsa will list all captured IP addresses and show each IP's bandwidth usage in the Utilization column of the "Summary" view. To view the interior bandwidth, select the "Local Subnets" of "IP Explorer " group in the "Project Explorer" dock window. Regard exterior bandwidth, select the "Internet Addresses" group from the "Project Explorer" dock window.
Top
We have a 70 Suite offices and 1 T1 sharing, the T1 goes down some times because some customers create Internet traffic with viruses and the usage of the T1 exceeds the 100%, can Colasoft Capsa help us find who is causing these issues?
A: If the 70 suite offices are connected via a middle-exchange-equipment (e.g. center switch) and supports Ethernet environment, Colasoft Capsa can be installed on any workstation which connects to the switch's mirroring port, then you can get all Internet traffic from your network.
Top
Can I monitor the traffic of my remote business network?
A: Yes. In order to monitor the traffic for your remote business network, you should install Colasoft Capsa on a workstation in your business network, and enable the Remote Desktop Access function of that workstation (Windows2000 Terminal Server, Norton PcAnywhere, VNC Server, etc.), then you can access to Colasoft Capsa via the local Remote Desktop client program.
Top
I'm on a LAN, when I run Colasoft Capsa and try to choose an adapter, the list does not show any adapters on my network.
A: Colasoft Capsa dynamically loads the NDIS protocol drivers it supports. However, the Windows NT and Windows 2000 security model does not allow non-administrator users to load and unload device drivers normally. If you meet such problems, use "regedit.exe" to delete the following keys in your registry, then reboot your machine and restart Colasoft Capsa.

Version 3.0:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCANDIS4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCAMPR4

Version 4.0:
Window98/Me
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CSCNDIS3 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CSCMPR3

WindowsNT4.0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CSCNDIS4 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CSCMPR4

Windows2000/XP/2003
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CSCNDIS5 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CSCMPR5

Version 5.0 (Windows2000/XP/2003):
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CSNPD50
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CSTDIDRV (Enterprise edition only)

Top
How can I use Colasoft Capsa to analyze traffic on other switch ports if our network is tied together with a switch?
A: Unlike hubs, switches prevent promiscuous sniffing. In a switched network environment, Colasoft Capsa (or any other packet analyzer) is limited to capturing broadcast and multicast packets and the traffic sent or received by the PC on which Colasoft Capsa is running.

However, most modern switches support "port mirroring", which is a feature that allows you to configure the switch to redirect the traffic that occurs on some or all ports to a designated monitoring port on the switch. By using this feature, you will able to monitor the entire LAN segment. Please refer to the documentation that comes with your switch for information on availability of this feature and configuration instructions.

If your switch does not support "port mirroring", you can install Colasoft Capsa on your Internet gateway (if applicable), or on a workstation connected to the same hub as your Internet gateway. In this way, you can monitor all network traffic between your Intranet and the Internet.

Various networking hardware manufacturers name the feature "port mirroring" differently. Click here for a reference list of hardware that support port mirroring.

Top
We use a Windows 2000 server and Exchange. We sent some emails but didn't see any information from Colasoft Capsa.
A: In most cases, Outlook communicates with Exchange server by using the "Exchange message protocol" which is not supported by Colasoft Capsa. However, you can configure Outlook and Exchange server to deliver email messages via SMTP and POP3 protocols. Please refer to the documentation that comes with your Exchange server for information on availability of this feature and configuration instructions.
Top
Why all the packets I see have a bad checksum?
A: Many GB adapters have the checksum offload parameters enabled by default. When this feature enabled, an adapter performs the cycle-intensive process of calculating CRC, the Windows TCP/IP stack does not calculate the IP and TCP checksums but leaves them as 0x0000. Colasoft Capsa collects the copy of each outgoing packet before it goes to the adapter, that is the reason why the checksum showed as bad. We have reproduced this issue on Intel Pro/1000 cards, but probably it may also occur on other adapters.

To fix this issue, you need to disable the adapter's Offload Transmit IP Checksum and Offload Transmit TCP Checksum feature in the advanced setting dialog.
Top
Can I change adapter when Colasoft Capsa is running?
A: Yes. Colasoft Capsa works on multiple adapters, you can change adapter when it is running, but some project data will be cleared, e.g. statistic values, graph data, TCP connections and the packets in the buffer, analyzers also will be reset.
Top
When Colasoft Capsa runs it slowly accumulates more RAM until the system runs out of physical memory, I set the packets to purge completely when the buffer is 100%, this helps but does not resolve the issue. Please advise.
A: Colasoft Capsa is designed for real-time network diagnosis, it saves all protocol statistic data for each endpoint, so the more endpoints or traffic in your LAN, the more memory usage required for analysis and diagnosis. The best way to optimize the program's performance is to filter out the packets you don't need to monitor. For example, sending a 50 MB file between two machines on your LAN can generate approximately 40,000 NetBIOS packets with the data transfer rate of 10 MBytes per second, which can be a heavy load for the application. But normally you don't to need to view every NetBIOS packet being sent, so you can configure Colasoft Capsa to capture IP packets only. Colasoft Capsa has a flexible filter system, including Simple Filter and Advanced Filter, you can fine-tune the application to display only the packets that you really need.
Top
I am using Colasoft Capsa 5.0 and would like to have an upgrade, can I share the packets with the new version?
A: Yes. Colasoft Capsa supports to import packet files from the previous version. You should first export packets to a file in *.cpf or *.cap format, then import it to the new version.
Top
Why I can not see any information in the Logs view when I send/receive emails via http string?
A: It is transmitted via HTTP protocol when you send/receive emails via web page. Colasoft Capsa cannot display these emails in the Logs view because of the Email Analyzer in Capsa analyzes emails based on SMTP and POP3 protocols.
Top
I cannot see any original content of an email by double-clicking it in the Email Messages list of Logs view. What can I do?
A: The reason is Colasoft Capsa will not save a copy of the captured emails in default. You should enable the Save Email Content and define a save path in the "Log" page of "Project Settings" dialog before capture.
Top
Can I locate the machines infected by worms with Colasoft Capsa?
A: Yes. There are two kinds of worm – email worm and OS worm.

Email worm
The infected machines will send out numerous emails in a little time which with the similar/same subject and the same attachments. Colasoft Capsa captures and reconstructs the emails transmitted in network, users can find out the infected machines with the relative information in the Email Logs.

OS worm
The infected machine will connect to all the other PCs in LAN with high frequency via the same port, which will occupy too much bandwidth. Users can easy detect the infected machines with the detailed information in the "Packets" view and "Conversations" view.

Top
Can I find out the reason of web slowdown with Colasoft Capsa?
A: Yes. The possible reasons cause web slowdown are the router between client and web server, the web server itself, the server script processing. You can find out the real reason with the information of accurate time using in the three periods provided by Colasoft Capsa.
Top
We configured IP address with DHCP in our network. How can I locate the trouble PC when we get network problem?
A: The MAC addresses of every PC are fixed though the IP addresses change frequently. You can get the details of all IP addresses, MAC addresses and hosts and their intrinsic relations in your network by scanning with Colasoft MAC Address Scanner. Then run Colasoft Capsa when the trouble occurred, you will conveniently locate the trouble PC and relative person with the scanner results and the captured packets.
Top
We need to add Port 10081 at the end of URL address when access our firewall via Web Interface. Why I can not find any information in the Logs view of Colasoft Capsa?
A: Colasoft Capsa analyzes the http browse based on the Port 80 in default. If you want to analyze http browse via other ports, such as Port 10081, please check the box before "Enable custom port" and click the button on the right in the "General" page of "Project Settings" dialog. Then you will see a "Custom Port" dialog window, which you can change the parameters of http to port 10081.
Top
We got IP conflicts in our network recently. Does Colasoft Capsa can help me?
A: Colasoft Capsa will reveal the detailed diagnoses information automatically, including MAC address conflict, if there is an IP address conflict in your network. With the MAC address conflict, you can find out the PC caused the conflict and resolve the conflict.
Top
Can I detect the BT download in our network with Colasoft Capsa?
A: Yes, Colasoft Capsa supports BT protocol. If there is a BT download in your network, you can get the BT download information, including the resource and destination PC, accurate time, and etc. In the Matrix view, you will see the PC execution BT download connected with huge internet addresses and its divergent matrix datagram.
Top
I need report files of the analysis, can Colasoft Capsa generate reports?
A: The "Reports" view of Colasoft Capsa can automatically generate reports of global network or a specific group, such as a subnet, a host or a protocol and save the reports in html format. You can even customize the statistic information and enhanced charts of the reports.
Top
There are HTTP Slow Response, FTP Slow Response, SMTP Slow Response and POP3 Slow Response in the diagnoses events when I run Colasoft Capsa. What's wrong and does it severe?
A: The Application Slow Response indicates your network speed is slow down but not severe. Colasoft Capsa identifies diagnosis events by the default value in the diagnosis module. You can custom the value by click the "Diagnosis" button in the toolbar, select the item and change its value (in ms).
Top
What the means of "Other" belongs to TCP or UDP protocol in the Protocols view?
A: The Other protocol belongs to TCP/UDP protocol suite in the "Protocols" view means Colasoft Capsa can not identify this protocol currently.
Top
Can I find out the resource with Colasoft Capsa if our server was attacked?
A: Colasoft Capsa captures and records all packets visited your server, including the attack packets. You can identify the real source of the attack packets by the captured packets.
Top
Our LAN is connected with a switch, but I can only detect my own web traffic. Why?
A: The web browse is a TCP communication which is neither broadcast nor multicast. You can only detect your own web traffic if the installation of Colasoft Capsa is incorrect. Colasoft Capsa works as bypass based on the Ethernet sniffer technology. If you are in a managed switch network, Colasoft Capsa should be installed on the PC connected to the mirror port of the switch. In an unmanaged switch network, on the contrary, you can only see your own web traffic because Colasoft Capsa can only capture local traffic and broadcasts in LAN. For more information of installation, please see Installation Layout.
Top
There are multiple IP addresses in a single NIC when I view the captured packets. Does it normal and why?
A: In general, there are several possibilities NIC configured multiple IP addresses:
  • In many cases, one NIC configured multiple IP addresses.
  • By masquerading as another host to spoof client and gateway, ARP attack often configured multiple IP addresses.

It is normal bind multiple IP addresses into one single NIC in the first and second conditions. But the third indicates the host is an ARP attacker.

Top
There are various departments in our company and each of them belongs to a different VLAN. Can Colasoft Capsa analyze traffic of each department and how?
A: Colasoft Capsa can capture and analyze packets over VLAN. You can set an address filter by IP range if you want to view the traffic of a specific department. Then you only will see the packets of the defined department in Colasoft Capsa.
Top
I double clicked a protocol in the Protocols view but can not see the corresponding packets in the popup window.
A: It is because of the total size of captured packets is bigger than your buffer size. When your project buffer is full, Colasoft Capsa will discard some older packets to keep the displayed packets up-to-date in default. The packets corresponding to the selected protocol was already discarded by the buffer when you click it, so you can see nothing in the popup window.
Top
How can I get clear view of some nodes when there are too many nodes in the Matrix view?
A: Though the "Matrix" view will display all captured information in default, you can get the information you focus on by set the "Display Options" of the "Matrix" view in Colasoft Capsa. You can view the maximum 100 nodes and maximum 100 conversations and even custom your own display options. In addition, you can choose the matrix type – Physical and IP, and traffic type – unicast, multicast and broadcast.
Top
When I imported packet capture, the time displayed in "Graphs" view does not match the one in "Packets" view. Why?
A: Colasoft Capsa will display the absolute time (the original capture time) in the "Diagnosis" view, "Conversations view, "Packets" view and "Logs" view if import a packet file. While the system will reanalyze the imported packets first and then display the analysis results in the "Summary" view and the "Graphs" view. So, the time displayed in these view are not the same.
Top
Colasoft MSN Monitor
This FAQ is about Colasoft MSN Monitor, please contact us if you can not find the answer for your questions.

  1. What is Colasoft MSN Monitor?
  2. What can I do with Colasoft MSN Monitor?
  3. What Operating Systems are supported by Colasoft MSN Monitor?
  4. How do I get the statistics of the MSN communications in my LAN?
  5. Can it show the display name of MSN Messenger accounts?
  6. What does it mean "Customize Name" in Colasoft MSN Monitor?
  7. How should I install the program to properly monitor the whole MSN communications in LAN?
  8. I can only see my own MSN communications, what is the reason?
  9. I select to show a MSN Messenger account by display name, but the Account Explorer dock window and the Summary tab view show different names.
  10. I want to find the messages of a specific MSN Messenger account, how can I do that?
  11. What should I do to get the MSN communication statistics of a whole LAN?
  12. What do the lines mean in the Conversation view? Can I change the line color?
  13. I run the program for 10 minutes but can not see any messages.
  14. What does it mean the "Current", "Today" and "Total" in the Overview/Summary view?
  15. My contacts are available but Coalsoft MSN Monitor shows them as offline.
  16. It can not find an available adapter for monitoring in my PC.
  17. I would like to delete some history messages, is it possible?


What is Colasoft MSN Monitor?
A: Colasoft MSN Monitor is a MSN Messenger statistics and message monitor. Based on packet analysis technology, Colasoft MSN Monitor focuses on MSN applications and instant message management. Besides capturing message contents, it also summarizes local MSN accounts and provides the statistics of account status, logins, message counts, contacts, message-related traffic that exceed traditional MSN message content "monitors" & "sniffers". The conversation matrix brings you a real-time insight into the MSN communications in your network.
Top
What can I do with Colasoft MSN Monitor?
A: If you have children, Colasoft MSN Monitor can let you know who your children's friends are and what they are usually talking about; if you are company managers, Colasoft MSN Monitor will reveal before you who are chatting with friends at work and how much time your employees spend on chatting; if you are a network administrator, Colasoft MSN Monitor will present the MSN packets and traffic transmitted in your LAN.
Top
What Operating Systems are supported by Colasoft MSN Monitor?
A:

Colasoft MSN Monitor supports Windows 2000 (SP4 or later), Windows XP (SP1 or later), Windows 2003 (SP2), and Windows Vista.

Top
How do I get the statistics of the MSN communications in my LAN?
A:

Colasoft MSN Monitor Pro provides the statistics of all MSN Messenger accounts in LAN. When you select the root node in the left Account Explorer dock window, you will see global statistics in the right Overview tab view; and when you select a MSN Messenger account, you will see account-related statistics in the Summary tab view.

Top
Can it show the display name or account name of MSN Messenger accounts?

A:

Yes. By default, Colasoft MSN Monitor show MSN Messenger accounts as display name; to show the account name, you can alter the selection with the "Show Name as" command in the View menu.
Top
What does it mean "Customize Name" in Colasoft MSN Monitor?

A:

Colasoft MSN Monitor Pro allows you to customize the name for local MSN accounts or account-related contacts. This feature is useful for you to quickly recognize some special accounts/contacts from numerous nodes.

To custom the name of a MSN account or contact, you need to select it in the left Account Explorer dock window first and open the right Summary tab view, then click the "Click to set" link to open a Customize Name dialog. The alias will go into effect immediately after your confirmation, you don't need to restart capturing or do any other operation. But please note that the alias can only be shown as "Display Name" and will only be applied to those new captured messages.

Top
How should I install the program to properly monitor the whole MSN communications in LAN?

A:

The proper installation of Colasoft MSN Monitor depends on your network topology, please refer the installation of Packet Analyzer - Colasoft Capsa in different network environments at http://www.colasoft.com/support/installation/.
Top
I can only see my own MSN communications, what is the reason?

A:

The most possible reason is that the installation of Colasoft MSN Monitor is incorrect. For example, if you are in a switched network and install the program on your computer rather than the mirror port, you would only see the MSN communications of your own. To learn more information about switched network and mirror port, please refer to the installation layouts of Packet Analyzer - Colasoft Capsa at http://www.colasoft.com/support/installation/.

Or if your installation is correct but choose your own account in the left Account Explorer dock window, you would only see your own data in the right "Message" tab view. In this case, you just need to switch to the root node or another MSN Messenger account in the Account Explorer.
Top
I select to show a MSN Messenger account by display name, but the Account Explorer dock window and the Summary tab view show different names.

A:

The Summary tab view of Colasoft MSN Monitor Pro presents the general information about your selected MSN Messenger account/contact, including account name, display name, personal message, and "Customize Name" that allows you to name the account/contact with an alias. If you have customized the name for an account, you would see that the Account Explorer shows its alias while the Summary tab view shows its real display name.
Top

I want to find the messages of a specific MSN Messenger account, how can I do that?

A:

By default, Colasoft MSN Monitor presents all messages captured in LAN. To view the conversations of a specific account, you need to select it in the left Account Explorer dock window and then switch the right tab views to get more information about it.

Additionally, the locating feature of Colasoft MSN Monitor can help you quickly find message-related account. For example, when you are browsing messages and would like to find the messages only sent/received by the current conversationer, you just need to click on its name, the program can automatically locate it in the left "Account Explorer" dock window.

Top

What should I do to get the MSN communication statistics of a whole LAN?

A:

To view global statistics of your LAN, you need to select the root node in the Account Explorer dock window and open the Overview tab view on the right (only available in Colasoft MSN Monitor Pro). The Overview tab view will present the statistics of the current monitoring, today monitoring and total monitoring since you initially run the program.
Top
What do the lines mean in the Conversation view? Can I change the line color?

A:

The Conversation tab view presents the MSN communications of your LAN in matrix way. In the matrix map, one line stands for one message, lines will be cascaded when there are more than one message, that is, the thicker the line is, the more messages sent/received between the peer nodes. The number in the bracket besides nodes indicates that how many messages have been sent by this node; additionally, when you move your mouse over it, you will see a text frame with the node-related information.

The line's color is customizable, you can click the icon from the Conversation - toolbar to open an options dialog and define colors for the ellipse, lines or nodes.

Top
I run the program for 10 minutes but can not see any messages.

A:

When you run the program for the first time you may not see any messages until a MSN communication initiated in your LAN. Colasoft MSN Monitor automatically saves captured messages in database and will keep the messages of the latest 15 days by default, so next time when you run the program you will see history messages even though currently there are no MSN communications in your LAN.
Top
What does it mean the "Current", "Today" and "Total" in the Overview/Summary view?

A:

The Overview tab view (when you select the root node in the Account Explorer) or Summary tab view (when you select an account or a contact in the Account Explorer), both are only available in Colasoft MSN Monitor Pro, presents the statistics related to your selection. The "Current" column shows the statistics of the current monitoring, "Today" is for the statistics monitored today and "Total" is for the total statistics since you initially run the program.
Top
My contacts are available but Coalsoft MSN Monitor shows them as offline.

A:

If you run Colasoft MSN Monitor before your contacts log in, you can see their real-time online status; however, if your contacts log in before you run the program, you can not see their current status until a conversation is initiated between. However, if the state of a contact changes, you can see that contact in the Account Explorer dock window.
Top
It can not find an available adapter for monitoring in my PC.

A:

Possible reason 1: Incorrect installation of adapter driver.
Solution: Uninstall Colasft MSN Monitor and reinstall it.

Possible reason 2: The current login user has no administrator authority.
Solution: Login as an administrator.

Possible reason 3: The network adapter is unsupported.
Solution: Upgrade the adapter driver to the latest version.

Possible reason 4: You have not restarted your computer after installed an update.
Solution: Restart your computer and run the program again.

Possible reason 5: The operating system platform is not supported, like 64bit Windows, etc.

Top
I would like to delete some history messages, is it possible?

A:

Yes, you can delete unwanted history messages and only save those in recent days. Please follow the steps below:

  • In "Options" menu select "Storage...".
  • Check the box "Delete messages older than" and choose or enter a day option.
  • Click "Ok" to confirm and you will see the old messages have been cleared.

    Please note that once you select to clear some history messages, they will be removed from database and will not be recovered.
  • Top

    Colasoft EtherLook
    This FAQ is about Colasoft EtherLook, please contact us if you can not find the answer for your questions.
    1. What is Colasoft EtherLook?
    2. What can I do with Colasoft EtherLook?
    3. I have a demo version of Colasoft EtherLook and a valid license key, but can't change the demo version to a valid registered version because I get no window to insert my license key. How can I do?
    4. I installed Colasoft EtherLook on an NT 4.0 service pack 6 computer and it constantly gives me a Dr. Watson screen and shuts down. It also could not be uninstalled completely.
    5. When I tried to install the demo version, I got the message: C:/WINNT/system32/W32N50.DLL. An error occurred while trying to replace the existing file; Delete File failed; code 5. The program didn't start running. What can I do?
    6. How can I make sure I'm no longer being monitored once this software is removed?
    7. Why I didn't see captured emails?
    8. How can I read the emails captured by Colasoft EtherLook?
    9. Why no data is displayed under the Referrer column in the Web view?
    10. One of my Intranet client has a different IP from yesterday's, I don't know why?
    11. I have 10 - 12 computers showed up in the Intranet, some have plus signs besides them which can be expanded to see more data but some others haven't, what is the reason for that?
    12. Dose Colasoft EtherLook support MS terminal services?
    13. Can Colasoft EtherLook capture the traffic on RAS/PPP adapters?
    14. I'm on a LAN, when I run the program and try to choose an adapter, there is no adapter listed.
    15. Dose Colasoft EtherLook support a wireless adapter?
    16. I can see the traffic of my computer, but get no traffic of other computers in the LAN.
    17. Can I use this product to monitor the traffic for a switched LAN?
    18. I run a test web server on my machine and browse to it from my machine, but I can't see any traffic when I run Colasoft EtherLook on the same machine.
    19. How can I set up a filter to focus on one IP?
    20. We use a Windows 2000 server and Exchange. The program doesn't show the emails we sent. The whole page stays blank.
    21. I am trying to monitor traffic speed and all entries show 0.00 KB/S.
    22. There is always blank on the Email and Login page. No data have been captured from the LAN but I can see a list of IPs that have connected to my PC.
    23. I sent 2 emails, 1 email sent with Pegasus Email was captured with no problem, but I did't see any data for the second email I sent with Outlook Express. What can I do to see the the second email?
    What is Colasoft EtherLook?
    A: Colasoft EtherLook is a powerful yet easy to use TCP/IP network monitor for the Windows-based platforms. With the abilities of real time monitoring all traffic flowing around the local network and to/from the Internet, you can manage and supervise the corporate network more easily and efficiently. The Traffic Analysis Module enables you to capture network traffic in real time, display the data received and sent by every host in LAN in different views. Additionally, Colasoft EtherLook has three advanced analysis modules: the Email Analysis Module captures email messages and restores its contents including sender, recipient, subject, protocol, etc.; the Web Analysis Module allows detailed tracking of Web accesses from the network; the Login Analysis Module analyzes all data logins within the network and records all related data.
    Top
    What can I do with Colasoft EtherLook?
    A: Colasoft EtherLook can be a helpful assistant for you to:
    • Diagnose and troubleshoot your network problems
    • Supervise network communications in your LAN
    • Enhance your network security
    • Solve problems for customers
    • Debug your network application
    • Learn network protocols
    • Find out what your children are doing on the internet
    Top
    I have a demo version of Colasoft EtherLook and a valid license key, but can't change the demo version to a valid registered version because I get no window to insert my license key. How can I do?
    A: The serial number/license key can only be applied to the full version. After you complete order process, a full version of Colasoft EtherLook will be sent to you electronically, you have to uninstall the demo version before install the full version.
    Top
    I installed Colasoft EtherLook on an NT 4.0 service pack 6 computer and it constantly gives me a Dr. Watson screen and shuts down. It also could not be uninstalled completely.
    A: Colasoft EtherLook dynamically loads the NDIS protocol drivers it supports. However, the Windows NT and Windows 2000 security model does not allow non-administrator users to load and unload device drivers normally. If you meet such problems, use "regedit.exe" to delete the following keys in your registry, then reboot your machine and restart Colasoft EtherLook.

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCANDIS4
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCAMPR4
    Top
    When I tried to install the demo version, I got the message: C:/WINNT/system32/W32N50.DLL. An error occurred while trying to replace the existing file; Delete File failed; code 5. The program didn't start running. What can I do?
    A: A possible reason for this problem is that you are running a sniffer or monitor software on your computer, or you have a previous version of Colasoft EtherLook. Before install Colasoft EtherLook, please make sure you have closed the sniffer or monitor software, or have uninstalled the previous version of Colasoft EtherLook.
    Top