When we get to the point in an investigation where we are about to break out Wireshark, the complexity of the packet analysis can seem quite daunting. And yet by covering a few key points can dramatically cut the time needed to analyze any diagnostic data.
In my previous post I covered the need to thoroughly understand a symptom. In this blog we'll look at the dangers looking for a common cause for multiple symptoms.
Imagine you are faced with a situation where users are complaining about three issues:
- Word documents should open in less than 5 seconds, but intermittently take more than 30 seconds.
- Excel workbooks should save in less than 15 seconds, but intermittently take more than 60 seconds.
- Opening an Outlook Inbox should take less than 20 seconds, but sometimes takes more than 3 minutes.
All problems are reported as having started at the same time, and there’s a widespread belief that they are being caused by a network issue. This is the point where alarm bells should start to ring.
Maybe some of the symptoms are down to the same root cause, but maybe they are not, and starting by assuming they are is likely to lead to a very frustrating time. The choice of a single symptom and ...