PacketSafari
Ecosystem overview

Virtual infrastructure packet investigation

Keep the private-cloud control plane. Investigate the virtual network.

Hypervisors, private-cloud platforms, and software-defined networks own VM lifecycle, switching, overlays, migration, and policy. When an alert or service failure remains unresolved, capture at the guest, host, vSwitch, virtual TAP, or approved overlay boundary and give PacketSafari the bounded PCAP.

Virtualization & private cloudContext → capture → investigation
Scope
VMware vSphere / ESXi / NSXAHV / FlowHyper-V / Azure LocalProxmox Virtual Environment
AcquireGuest · vSwitch · host captureauthorized incident PCAP
InvestigatePacketSafariCore Engine · Agent · report
Result outExact evidence returns to the team that can act.
Category owns

Run and connect virtual machines, manage hosts and clusters, enforce virtual-network policy, and expose infrastructure health and events.

Acquisition path

VM alert or service failure → guest, vSwitch, host, virtual TAP, or virtual packet broker capture → bounded PCAP → PacketSafari investigation.

PacketSafari owns

Test east-west traffic, session drops, overlay behavior, migration symptoms, and network-versus-guest explanations against the selected packet record.

Representative products

Different jobs. One clean handoff.

These are representative ecosystem products, not partner badges or certification claims. Capabilities and packet access vary by edition, license, deployment, and configuration.

Vendor / productPrimary rolePacket boundaryFitPacketSafari value

Enterprise virtualization, virtual switching, overlays, microsegmentation, and private-cloud networking

Capture can occur in the guest, at ESXi or virtual-switch boundaries, or through NSX and adjacent visibility tooling.

Strong handoff

Investigate east-west traffic, overlays, resets, retransmissions, and guest-versus-network disputes without replacing vSphere or NSX.

Hyperconverged virtualization, virtual networking, microsegmentation, and policy

Traffic and policy context live in AHV and Flow; packet acquisition depends on the host and virtual-network design.

Complementary

Use the affected VM, policy, path, and time window to scope a packet investigation.

Windows virtualization and distributed on-premises infrastructure

Pktmon can observe multiple Windows networking components, including virtualized and SDN paths, and export PCAPNG.

Strong handoff

Trace packet paths and supported drop reasons inside the Windows stack, then investigate the portable capture.

Open-source KVM and container virtualization with clustering and software-defined networking

Capture at the guest, Linux bridge, Open vSwitch, host interface, or adjacent virtual visibility point.

Strong handoff

Separate guest behavior from bridge, VLAN, overlay, host, and upstream-network behavior.

OpenInfra FoundationOpenStack

Private-cloud compute, networking, storage, identity, and orchestration

Capture at an instance, compute host, tap device, namespace, virtual router, overlay, or mirrored Neutron path as authorized.

Strong handoff

Investigate tenant, overlay, routing, security-group, and service-chain questions with exact packet timing.

Open sourceKVM / libvirt

Linux virtualization and virtual network management

Capture at the guest interface, tap, bridge, Open vSwitch, host NIC, or namespace.

Strong handoff

Make the observation point explicit and test whether failure belongs to the guest, host, virtual switch, or upstream path.

Run and manage virtual machines alongside containers on Kubernetes

Workload and node observability can identify VM traffic; capture paths depend on the primary or secondary network design.

Complementary

Carry VM, node, namespace, and network context into a bounded packet investigation.

Decision guide

Use each layer for the decision it owns.

PacketSafari adds depth after a capture exists. It does not become the continuous monitor, enforcement point, access broker, packet broker, or recorder.

Do you need VM lifecycle, overlay, or virtual-network control?

Use the hypervisor, private-cloud platform, and SDN control plane.

Can the physical TAP see the disputed east-west exchange?

If not, capture at the guest, host, vSwitch, virtual TAP, namespace, or overlay boundary that can.

Is responsibility disputed between the guest and network?

Compare captures at two authorized boundaries and use PacketSafari to test the competing explanations.