Skip to content
OBSERVE. ANALYZE. ACT.
Support Login

APM / Application Performance Monitoring

Understand application behavior where it crosses the network.

Bring application context to a network investigation. 01Layer combines live traffic, uploaded captures, protocol metadata, and QoS analysis so teams can examine service behavior and test the effect of a change.

Live and captured application traffic provides protocol context and timing evidence for investigation, comparison, and validation.
View the workflow at full size

See the application context

Review supported protocol activity and the endpoints involved.

Investigate the event

Focus the time window and examine the supporting traffic evidence.

Verify the change

Compare observed behavior using repeatable analysis and validation.

The network view of the application

Connect service behavior to observed traffic.

The workflow starts with traffic evidence: current site capture, files uploaded by a remote team, or a monitored folder. Apply consistent targeting and analysis across these sources.

Observe

Bring the evidence together

Combine continuing capture with PCAP or PCAPng intake. Use source groups and time windows to keep the investigation focused on the service and site involved.

Joint capture and PCAP analysis

Understand

Inspect application context

Explore supported DNS, HTTP, TLS, email, and other protocol profiles alongside endpoint, session, network, and QoS context.

Metadata capability

Validate

Compare the behavior

Use captured, replayed, or generated traffic with timing and counters to review service treatment and the effect of a configuration change.

QoS Analysis

Protocol-level evidence

Follow the dependencies visible in the traffic.

Start with the protocols and endpoints involved in the application path. Select the profiles that match the question and use retained capture evidence for closer inspection.

Application investigation context
ViewWhat it contributesHow to use it
DNSName queries, responses, latency, response codes, and resource-record context.Examine name-service activity in the incident window and relate it to the affected endpoints.
HTTP and TLSHTTP method, host, URI, client and server addresses; TLS version, cipher, server name, resumption status, and alert fields.Identify the observed service and inspect the connections associated with the report.
Sessions and endpointsEndpoints, service, session duration, byte counts, connection state, and missed-byte signals.Narrow the traffic to the client, server, site, or capture source involved.
QoS and traffic timingCounters, timing, and observed traffic treatment.Compare the traffic behavior before and after a change or under a chosen workload.
Supporting protocolsSupported email, FTP, QUIC, SSH, RDP, and file-transfer profiles.Inspect the protocol context relevant to the service being investigated.

This workflow provides the application view available from network traffic. The visibility depends on the collection point, retained data, and exposed protocol fields; encrypted content requires its own access and analysis context.

Inside the analysis workflow

Inspect the transaction. Compare the session.

HTTP records expose the method, host, URI, endpoints, and transaction depth. Session and connection views add duration, byte counts, connection state, and missed-byte signals to help identify resets, unstable flows, or performance outliers.

From symptom to evidence

Give the investigation a repeatable path.

Use one scope for the reported symptom, the selected traffic, and the findings shared between teams.

  1. Define the service and time window

    Record the affected application, endpoints, site, and incident interval. Select the live source or uploaded evidence that covers that observation.

  2. Target the relevant traffic

    Apply IP, IP-list, IP-range, BPF, or regular-expression targeting as appropriate. Merge capture timestamps when multiple sources need a common chronology.

  3. Review context and treatment

    Inspect supported protocol profiles, session and endpoint context, traffic timing, and QoS evidence. Return to the selected trace when a detail needs verification.

  4. Document the comparison

    Use analytic tables, dashboards, or a notebook to retain the method, source scope, and findings. Export the relevant trace or dataset for the next team.

Test the next decision

Carry the evidence into validation.

When a network or service change is proposed, use a reproducible workload and a defined observation window to assess the result.

Reproduce a traffic condition

Use captured traffic with Packet Replay, or select the documented stateless generation and application-simulation tools when a controlled workload is needed.

Choose rate, duration, and workload profile to represent the condition being examined, then collect the resulting traffic for comparison.

Validation tools

Compare expected and observed treatment

QoS Analysis combines generated, replayed, or captured traffic with timing and counters. Review the service behavior against the intended treatment.

Use a notebook when the comparison needs a repeatable custom analysis, visualization, or report beyond a fixed view.

QoS analysis workflow

Operational practice

Build a useful evidence window.

Collection and retention choices determine which application questions can be investigated later.

Observation coverage
Select traffic sources that cover the application path and the incident context. Keep source identity attached to the evidence.
Retention and retrieval
Align metadata retention and raw trace availability with the expected response and investigation time.
Comparable analysis
Use consistent source groups, targeting, and time windows when comparing sites or conditions.
Shared findings
Record the chosen evidence, method, and observed result in the notebook or exported report so another team can reproduce the review.

Keep exploring

From overview to operation.

Open the function descriptions, component controls, and related workflows behind this capability.

Bring application context to your network decisions.

Discuss the sources, service requirements, and deployment that fit your operation.

Talk to our team