Virtual infrastructure packet investigation
Keep the private-cloud control plane. Investigate the virtual network.
Hypervisors, private-cloud platforms, and software-defined networks own VM lifecycle, switching, overlays, migration, and policy. When an alert or service failure remains unresolved, capture at the guest, host, vSwitch, virtual TAP, or approved overlay boundary and give PacketSafari the bounded PCAP.
Run and connect virtual machines, manage hosts and clusters, enforce virtual-network policy, and expose infrastructure health and events.
VM alert or service failure → guest, vSwitch, host, virtual TAP, or virtual packet broker capture → bounded PCAP → PacketSafari investigation.
Test east-west traffic, session drops, overlay behavior, migration symptoms, and network-versus-guest explanations against the selected packet record.
Representative products
Different jobs. One clean handoff.
These are representative ecosystem products, not partner badges or certification claims. Capabilities and packet access vary by edition, license, deployment, and configuration.
Enterprise virtualization, virtual switching, overlays, microsegmentation, and private-cloud networking
Capture can occur in the guest, at ESXi or virtual-switch boundaries, or through NSX and adjacent visibility tooling.
Strong handoffInvestigate east-west traffic, overlays, resets, retransmissions, and guest-versus-network disputes without replacing vSphere or NSX.
Hyperconverged virtualization, virtual networking, microsegmentation, and policy
Traffic and policy context live in AHV and Flow; packet acquisition depends on the host and virtual-network design.
ComplementaryUse the affected VM, policy, path, and time window to scope a packet investigation.
Windows virtualization and distributed on-premises infrastructure
Pktmon can observe multiple Windows networking components, including virtualized and SDN paths, and export PCAPNG.
Strong handoffTrace packet paths and supported drop reasons inside the Windows stack, then investigate the portable capture.
Open-source KVM and container virtualization with clustering and software-defined networking
Capture at the guest, Linux bridge, Open vSwitch, host interface, or adjacent virtual visibility point.
Strong handoffSeparate guest behavior from bridge, VLAN, overlay, host, and upstream-network behavior.
Private-cloud compute, networking, storage, identity, and orchestration
Capture at an instance, compute host, tap device, namespace, virtual router, overlay, or mirrored Neutron path as authorized.
Strong handoffInvestigate tenant, overlay, routing, security-group, and service-chain questions with exact packet timing.
Linux virtualization and virtual network management
Capture at the guest interface, tap, bridge, Open vSwitch, host NIC, or namespace.
Strong handoffMake the observation point explicit and test whether failure belongs to the guest, host, virtual switch, or upstream path.
Run and manage virtual machines alongside containers on Kubernetes
Workload and node observability can identify VM traffic; capture paths depend on the primary or secondary network design.
ComplementaryCarry VM, node, namespace, and network context into a bounded packet investigation.
Decision guide
Use each layer for the decision it owns.
PacketSafari adds depth after a capture exists. It does not become the continuous monitor, enforcement point, access broker, packet broker, or recorder.
Do you need VM lifecycle, overlay, or virtual-network control?
Use the hypervisor, private-cloud platform, and SDN control plane.
Can the physical TAP see the disputed east-west exchange?
If not, capture at the guest, host, vSwitch, virtual TAP, namespace, or overlay boundary that can.
Is responsibility disputed between the guest and network?
Compare captures at two authorized boundaries and use PacketSafari to test the competing explanations.

