SlideShare a Scribd company logo
IT Performance Problems
Session Date & Time
• Date: Wednesday, June 29, 2016
Time: 1100-1145
Location: Tuscany Ballroom
• Bill Alderson responds to Information Technology high
visibility, high stakes technical problems. Network outage,
slowness, slow applications or disasters affecting
government and commercial Information Technology
Enterprise environments. ABC News told the story of how
Bill and his team helped restore communications at the
Pentagon immediately following 911. Bill assisted with six
deployments to Iraq and Afghanistan requested by Army
G2, Joint Chiefs and US Central Command diagnosing
Biometrics and others critical systems. One of his missions
is to help executives and technologists see both technical
and leadership root causes that can be obviated through
common sense best practices.
Bill Alderson Infographic Bio
• Deep packet analysis remains essential for definitive irrefutable diagnosis
and optimization of complex systems. Bill demonstrates the tools,
techniques and methods used to annotate complex technology findings so
that technologists, managers, executives and vendors can agree on root
cause. Once the problem is identified and agreed upon the true pinpoint
mitigation can begin. The days of shotgun style "forklift wholesale
upgrades" on everything have passed. We must optimize existing assets
allowing them to perform well.
Bill has proven ability to optimize large scale networks and applications
from experience in analyzing the Pentagon immediately following 911,
analysis of Biometrics applications across Iraq and Afghanistan, numerous
optimizations of Joint Chiefs of Staff and OSD network analysis. Experience
from analysis of the largest 100 commercial enterprise networks such as
Stock Exchanges, Financial, Insurance and Healthcare institutions will be
demonstrated with annotated examples for CIO, Executives and top level
technologists.
IT Critical Problem Resolution
Technology and Psychology
bill@apalytics.com
“Swiss Army Knife” Portfolio of Tools
Select Well.
Avoid Spending
Only on “Suites”
All-in-one-tools
Although easier to “buy”
don’t solve many problems.
They leave you “broke and broken”
with a gold plated toolset.
Optimization Troubleshooting Phases
Preparation & Setup
Analysis & Iteration
Reporting & Presentation
Problem Management
Down - Intermittent - Slow
Technical vs. Leadership Root Cause
The Needle
The Environment
Packet Traces
Store Every Packet?
Who’s can and is going to analyze them and when?
Finding The Stack With The Problem
Finding The Needle
Measured at the Server
Fast TCP connect
time. Fast Ack from
F5 does not show
true client response
time which is why
Apalytics provided
Internet Monitoring.
1.4 second Get
response is very slow
which is why detailed
platform and
application analysis
was performed.
The 2nd & 3rd Gets
were fast at 1
millisecond proving
some commands are
CF Longest Requests
1,958,266ms = ~32 minutes from one request
391,692ms = ~7 minutes
Page Analysis from the Internet
DNS does not play a role in slowness. Connection time varies and at time approaches 200 milliseconds which can be at the platform, internet, network, load
balancer or firewalls. Connection delay analysis will require multiple capture points to definitively pinpoint and should be considered when multi-point
capture test points can be configured at the Security Tap devices. But that is not material for improvement of this application at this timeFirst byte time is
the most concerning issue in the infrastructure. Last byte time is also a concern as it appears that platform TCP/IP stack services are slow to move data out
onto the wire after the first byte has started. It may also be that platform improvements may improve both response times and output speed. Page load
time is a composite of all elements of the page that must come together to provide the user with the visual page and the main context of the query. This
too is concerning, but it is caused by the slowness of the individual components of the page as they add serially to the response time which are represented
in the main concerns. An example of the total page would be small visual images and data making up the user interface view (i.e., logos) that are not part of
a computational or lookup, but rather a static image that should be served rapidly by the server.
Network Intrinsic Application Analysis
Multi-tier Analysis
Multi-Tier Identification
Application Monitoring Design Phase
Multi-tier Macro vs. Micro
Event
Process
Net-Ser-Tr-Sw-Q
Security Auth
User Click
Client
Network
WebSvr
Network
AppSrv
Network
SQLSvr
Network
AppSvr
Network
Mainframe
Network
AppSvr
Network
WebSvr
Network
Client
User Display UpdateMacro Response
Time
Micro
Response
Time
HTTP Post
from client
Web1
Middlewa
re
155ms
HTTP / SQL Multi-tier 1
Back to client
With HTTP
SQL Calls complete
Query and returns
Rows to Web1
SQL Calls finish .497
SQL Call start -.231
SQL Resp Time =.266
Web1
Middleware
12ms
HTTP / SQL Multi-tier 2
Logon A is 72
milliseconds…
Logon B is 420
milliseconds!
Oracle Logon Slow
Micro-Analysis Phase
Web App I/F #1&2 SQL TransLogger MF#1 MF#2 Time
Breakdown
TCP Satellite Retrans 3.5 Seconds
Processing Analysis
Packet Loss Analysis
Citrix Session Abort Signature “Chernobyl Packet”
The packet that
evidenced a problem
on a Citrix server.
This pattern was used
as a signature on the
Infinistream Sniffers
to find these
problems until they
were remediated.
Prior to this users
were stuck in this
cycle for hours.
Citrix User Filer Access Error Details
Blind vs. Pinpoint Upgrades
Blind Upgrade = Shotgun Approach = Forklift Upgrade
Root Cause Optimization
Definitive Root Cause Analysis Pinpoint Cause Measure ROI Potential
Pinpoint Purchases Validate & Prove ROI Award Innovation
Optimization
Root
Cause
Analysis
IT Critical Problem Resolution
Technology and Psychology
bill@apalytics.com

More Related Content

What's hot (20)

PPTX
Splunk for Security Breakout Session
Splunk
 
PPT
Information Security
Mohit8780
 
PDF
How VPNs and Firewalls Put Your Organization at Risk
Cyxtera Technologies
 
PDF
SplunkLive! London - Splunk App for Stream & MINT Breakout
Splunk
 
PDF
GDPR Compliance Countdown - Is your Application environment ready?
QualiQuali
 
PPTX
Webcast Series #3: GDPR Deadline Readiness and Impact to Global Organizations...
Qualys
 
PDF
SCADA Security: The Five Stages of Cyber Grief
Lancope, Inc.
 
PPTX
SplunkLive! Austin Customer Presentation - Dell
Splunk
 
PPTX
Building an AppSec Team Extended Cut
Mike Spaulding
 
PPTX
Jack Nichelson - Information Security Metrics - Practical Security Metrics
centralohioissa
 
PDF
Gavin Hill - Lessons From the Human Immune System
centralohioissa
 
PDF
Top Application Security Threats
ColumnInformationSecurity
 
PDF
A Symantec Advisory Guide Migrating to Symantec™ Validation and ID Protection...
Symantec
 
PDF
Disaster recovery glossary
singlehopsn
 
PPTX
Splunk at Weill Cornell Medical College
Splunk
 
PDF
Ken Czekaj & Robert Wright - Leveraging APM NPM Solutions to Compliment Cyber...
centralohioissa
 
PDF
Cloud Security Myths Vs Facts
OPAQ
 
PDF
Solution Brief
webhostingguy
 
PPT
SolarWinds Log & Event Manager vs Splunk. What's the Difference?
SolarWinds
 
PDF
u10a1 Network and Security Architecture _FINAL - Kent Haubein
Kent Haubein
 
Splunk for Security Breakout Session
Splunk
 
Information Security
Mohit8780
 
How VPNs and Firewalls Put Your Organization at Risk
Cyxtera Technologies
 
SplunkLive! London - Splunk App for Stream & MINT Breakout
Splunk
 
GDPR Compliance Countdown - Is your Application environment ready?
QualiQuali
 
Webcast Series #3: GDPR Deadline Readiness and Impact to Global Organizations...
Qualys
 
SCADA Security: The Five Stages of Cyber Grief
Lancope, Inc.
 
SplunkLive! Austin Customer Presentation - Dell
Splunk
 
Building an AppSec Team Extended Cut
Mike Spaulding
 
Jack Nichelson - Information Security Metrics - Practical Security Metrics
centralohioissa
 
Gavin Hill - Lessons From the Human Immune System
centralohioissa
 
Top Application Security Threats
ColumnInformationSecurity
 
A Symantec Advisory Guide Migrating to Symantec™ Validation and ID Protection...
Symantec
 
Disaster recovery glossary
singlehopsn
 
Splunk at Weill Cornell Medical College
Splunk
 
Ken Czekaj & Robert Wright - Leveraging APM NPM Solutions to Compliment Cyber...
centralohioissa
 
Cloud Security Myths Vs Facts
OPAQ
 
Solution Brief
webhostingguy
 
SolarWinds Log & Event Manager vs Splunk. What's the Difference?
SolarWinds
 
u10a1 Network and Security Architecture _FINAL - Kent Haubein
Kent Haubein
 

Viewers also liked (18)

PPTX
ssddeerr
Shubham Gautam
 
DOC
S Adeyemo's CVcurrent
Sunmola Adeyemo Mcipp
 
PDF
CAD és CAE Technikák II. Előadás III. - Timothy István Erdei & Zsolt Molnár
unidebvmt
 
PDF
TOR
LIVI DEODOR
 
DOCX
Informatica ii-mirella
mirella1994
 
PDF
An ideal 10 gbe interface why 10gbase t
Fern Xu
 
PDF
CAD és CAE Technikák II. Előadás I. - Timothy István Erdei & Zsolt Molnár
unidebvmt
 
PPTX
теорема вієта
orestznak
 
DOCX
Reformas constitucionales 12
Edwiin Manueel
 
PDF
Roteiro Cidade Criativa
cultcultura
 
PPTX
Polimetalicos
Ruben Cabanillas Requiz
 
RTF
Document
rovinignacio_04
 
PPT
Gsm VS cdma
Ghanshyam Dusane
 
PPT
Motiverende gespreksvoering, Jean-Pierre Hoengenaert
VIGeZ
 
PPTX
Színpszichológia - Timotei-Robotics - Timotei István Erdei
Timotei Robotics
 
PPT
E Caudera Strategic Downturn
Ezio Caudera
 
PPT
Guia didactica flauta dulce
JAVIER RAMIREZ
 
ssddeerr
Shubham Gautam
 
S Adeyemo's CVcurrent
Sunmola Adeyemo Mcipp
 
CAD és CAE Technikák II. Előadás III. - Timothy István Erdei & Zsolt Molnár
unidebvmt
 
Informatica ii-mirella
mirella1994
 
An ideal 10 gbe interface why 10gbase t
Fern Xu
 
CAD és CAE Technikák II. Előadás I. - Timothy István Erdei & Zsolt Molnár
unidebvmt
 
теорема вієта
orestznak
 
Reformas constitucionales 12
Edwiin Manueel
 
Roteiro Cidade Criativa
cultcultura
 
Document
rovinignacio_04
 
Gsm VS cdma
Ghanshyam Dusane
 
Motiverende gespreksvoering, Jean-Pierre Hoengenaert
VIGeZ
 
Színpszichológia - Timotei-Robotics - Timotei István Erdei
Timotei Robotics
 
E Caudera Strategic Downturn
Ezio Caudera
 
Guia didactica flauta dulce
JAVIER RAMIREZ
 
Ad

Similar to IT Performance Problems (20)

PPTX
Citrix Troubleshooting 101: How to Resolve and Prevent Business-Impacting Cit...
eG Innovations
 
PDF
Brighttalk what should we be monitoring - final
Andrew White
 
PPTX
Citrix Troubleshooting 101
eG Innovations
 
PDF
Brighttalk learning to cook- network management recipes - final
Andrew White
 
PPTX
Citrix troubleshooting 101
eG Innovations
 
PPTX
Information Technology - Discover the Root Cause and Develop a solution throu...
John Hudson
 
PPT
Fast-teks Remote Managed Services
Joe Hanold
 
PPT
Operational Improvements
krkingsley
 
PDF
ITIL and Service Management
William Buddy Gillespie ITIL Certified
 
PPT
NSI Net Factor Advantage
Nirico Systems Inc.
 
PPTX
Free Netflow analyzer training - diagnosing_and_troubleshooting
ManageEngine, Zoho Corporation
 
PPTX
Performance Forensics - Understanding Application Performance
Alois Reitbauer
 
PDF
Angelbeat -Cut Your Troubleshooting_Time-In-Half
Rick Kingsley
 
PDF
Rac 12c optimization
Riyaj Shamsudeen
 
PPTX
Key to optimal end user experience
ManageEngine, Zoho Corporation
 
PPT
T3 Consortium's Performance Center of Excellence
veehikle
 
PDF
Bottlenecks exposed
Vikas Singh
 
PPTX
Troubleshooting the Most Common Citrix Complaints for Remote Workers
eG Innovations
 
PPT
Big Events Cause Network Mayhem
PacketTrap Msp
 
PPTX
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...
ManageEngine, Zoho Corporation
 
Citrix Troubleshooting 101: How to Resolve and Prevent Business-Impacting Cit...
eG Innovations
 
Brighttalk what should we be monitoring - final
Andrew White
 
Citrix Troubleshooting 101
eG Innovations
 
Brighttalk learning to cook- network management recipes - final
Andrew White
 
Citrix troubleshooting 101
eG Innovations
 
Information Technology - Discover the Root Cause and Develop a solution throu...
John Hudson
 
Fast-teks Remote Managed Services
Joe Hanold
 
Operational Improvements
krkingsley
 
ITIL and Service Management
William Buddy Gillespie ITIL Certified
 
NSI Net Factor Advantage
Nirico Systems Inc.
 
Free Netflow analyzer training - diagnosing_and_troubleshooting
ManageEngine, Zoho Corporation
 
Performance Forensics - Understanding Application Performance
Alois Reitbauer
 
Angelbeat -Cut Your Troubleshooting_Time-In-Half
Rick Kingsley
 
Rac 12c optimization
Riyaj Shamsudeen
 
Key to optimal end user experience
ManageEngine, Zoho Corporation
 
T3 Consortium's Performance Center of Excellence
veehikle
 
Bottlenecks exposed
Vikas Singh
 
Troubleshooting the Most Common Citrix Complaints for Remote Workers
eG Innovations
 
Big Events Cause Network Mayhem
PacketTrap Msp
 
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...
ManageEngine, Zoho Corporation
 
Ad

Recently uploaded (20)

PPTX
Feb 2021 Ransomware Recovery presentation.pptx
enginsayin1
 
PPT
tuberculosiship-2106031cyyfuftufufufivifviviv
AkshaiRam
 
PPTX
Listify-Intelligent-Voice-to-Catalog-Agent.pptx
nareshkottees
 
PPTX
05_Jelle Baats_Tekst.pptx_AI_Barometer_Release_Event
FinTech Belgium
 
PDF
apidays Singapore 2025 - Building a Federated Future, Alex Szomora (GSMA)
apidays
 
PPTX
apidays Singapore 2025 - Designing for Change, Julie Schiller (Google)
apidays
 
PDF
Using AI/ML for Space Biology Research
VICTOR MAESTRE RAMIREZ
 
PPTX
apidays Helsinki & North 2025 - Agentic AI: A Friend or Foe?, Merja Kajava (A...
apidays
 
PDF
Research Methodology Overview Introduction
ayeshagul29594
 
PPTX
Aict presentation on dpplppp sjdhfh.pptx
vabaso5932
 
PDF
The Best NVIDIA GPUs for LLM Inference in 2025.pdf
Tamanna36
 
PPTX
BinarySearchTree in datastructures in detail
kichokuttu
 
PDF
apidays Singapore 2025 - How APIs can make - or break - trust in your AI by S...
apidays
 
PPT
Growth of Public Expendituuure_55423.ppt
NavyaDeora
 
PDF
apidays Singapore 2025 - Trustworthy Generative AI: The Role of Observability...
apidays
 
PPTX
SlideEgg_501298-Agentic AI.pptx agentic ai
530BYManoj
 
PDF
apidays Singapore 2025 - From API Intelligence to API Governance by Harsha Ch...
apidays
 
PDF
OOPs with Java_unit2.pdf. sarthak bookkk
Sarthak964187
 
PPTX
apidays Helsinki & North 2025 - APIs at Scale: Designing for Alignment, Trust...
apidays
 
PDF
Technical-Report-GPS_GIS_RS-for-MSF-finalv2.pdf
KPycho
 
Feb 2021 Ransomware Recovery presentation.pptx
enginsayin1
 
tuberculosiship-2106031cyyfuftufufufivifviviv
AkshaiRam
 
Listify-Intelligent-Voice-to-Catalog-Agent.pptx
nareshkottees
 
05_Jelle Baats_Tekst.pptx_AI_Barometer_Release_Event
FinTech Belgium
 
apidays Singapore 2025 - Building a Federated Future, Alex Szomora (GSMA)
apidays
 
apidays Singapore 2025 - Designing for Change, Julie Schiller (Google)
apidays
 
Using AI/ML for Space Biology Research
VICTOR MAESTRE RAMIREZ
 
apidays Helsinki & North 2025 - Agentic AI: A Friend or Foe?, Merja Kajava (A...
apidays
 
Research Methodology Overview Introduction
ayeshagul29594
 
Aict presentation on dpplppp sjdhfh.pptx
vabaso5932
 
The Best NVIDIA GPUs for LLM Inference in 2025.pdf
Tamanna36
 
BinarySearchTree in datastructures in detail
kichokuttu
 
apidays Singapore 2025 - How APIs can make - or break - trust in your AI by S...
apidays
 
Growth of Public Expendituuure_55423.ppt
NavyaDeora
 
apidays Singapore 2025 - Trustworthy Generative AI: The Role of Observability...
apidays
 
SlideEgg_501298-Agentic AI.pptx agentic ai
530BYManoj
 
apidays Singapore 2025 - From API Intelligence to API Governance by Harsha Ch...
apidays
 
OOPs with Java_unit2.pdf. sarthak bookkk
Sarthak964187
 
apidays Helsinki & North 2025 - APIs at Scale: Designing for Alignment, Trust...
apidays
 
Technical-Report-GPS_GIS_RS-for-MSF-finalv2.pdf
KPycho
 

IT Performance Problems

  • 2. Session Date & Time • Date: Wednesday, June 29, 2016 Time: 1100-1145 Location: Tuscany Ballroom
  • 3. • Bill Alderson responds to Information Technology high visibility, high stakes technical problems. Network outage, slowness, slow applications or disasters affecting government and commercial Information Technology Enterprise environments. ABC News told the story of how Bill and his team helped restore communications at the Pentagon immediately following 911. Bill assisted with six deployments to Iraq and Afghanistan requested by Army G2, Joint Chiefs and US Central Command diagnosing Biometrics and others critical systems. One of his missions is to help executives and technologists see both technical and leadership root causes that can be obviated through common sense best practices.
  • 5. • Deep packet analysis remains essential for definitive irrefutable diagnosis and optimization of complex systems. Bill demonstrates the tools, techniques and methods used to annotate complex technology findings so that technologists, managers, executives and vendors can agree on root cause. Once the problem is identified and agreed upon the true pinpoint mitigation can begin. The days of shotgun style "forklift wholesale upgrades" on everything have passed. We must optimize existing assets allowing them to perform well. Bill has proven ability to optimize large scale networks and applications from experience in analyzing the Pentagon immediately following 911, analysis of Biometrics applications across Iraq and Afghanistan, numerous optimizations of Joint Chiefs of Staff and OSD network analysis. Experience from analysis of the largest 100 commercial enterprise networks such as Stock Exchanges, Financial, Insurance and Healthcare institutions will be demonstrated with annotated examples for CIO, Executives and top level technologists.
  • 6. IT Critical Problem Resolution Technology and Psychology [email protected]
  • 7. “Swiss Army Knife” Portfolio of Tools Select Well. Avoid Spending Only on “Suites” All-in-one-tools Although easier to “buy” don’t solve many problems. They leave you “broke and broken” with a gold plated toolset.
  • 18. Store Every Packet? Who’s can and is going to analyze them and when?
  • 19. Finding The Stack With The Problem
  • 21. Measured at the Server Fast TCP connect time. Fast Ack from F5 does not show true client response time which is why Apalytics provided Internet Monitoring. 1.4 second Get response is very slow which is why detailed platform and application analysis was performed. The 2nd & 3rd Gets were fast at 1 millisecond proving some commands are
  • 22. CF Longest Requests 1,958,266ms = ~32 minutes from one request 391,692ms = ~7 minutes
  • 23. Page Analysis from the Internet DNS does not play a role in slowness. Connection time varies and at time approaches 200 milliseconds which can be at the platform, internet, network, load balancer or firewalls. Connection delay analysis will require multiple capture points to definitively pinpoint and should be considered when multi-point capture test points can be configured at the Security Tap devices. But that is not material for improvement of this application at this timeFirst byte time is the most concerning issue in the infrastructure. Last byte time is also a concern as it appears that platform TCP/IP stack services are slow to move data out onto the wire after the first byte has started. It may also be that platform improvements may improve both response times and output speed. Page load time is a composite of all elements of the page that must come together to provide the user with the visual page and the main context of the query. This too is concerning, but it is caused by the slowness of the individual components of the page as they add serially to the response time which are represented in the main concerns. An example of the total page would be small visual images and data making up the user interface view (i.e., logos) that are not part of a computational or lookup, but rather a static image that should be served rapidly by the server.
  • 28. Multi-tier Macro vs. Micro Event Process Net-Ser-Tr-Sw-Q Security Auth User Click Client Network WebSvr Network AppSrv Network SQLSvr Network AppSvr Network Mainframe Network AppSvr Network WebSvr Network Client User Display UpdateMacro Response Time Micro Response Time
  • 30. Back to client With HTTP SQL Calls complete Query and returns Rows to Web1 SQL Calls finish .497 SQL Call start -.231 SQL Resp Time =.266 Web1 Middleware 12ms HTTP / SQL Multi-tier 2
  • 31. Logon A is 72 milliseconds… Logon B is 420 milliseconds! Oracle Logon Slow
  • 32. Micro-Analysis Phase Web App I/F #1&2 SQL TransLogger MF#1 MF#2 Time Breakdown
  • 33. TCP Satellite Retrans 3.5 Seconds
  • 36. Citrix Session Abort Signature “Chernobyl Packet” The packet that evidenced a problem on a Citrix server. This pattern was used as a signature on the Infinistream Sniffers to find these problems until they were remediated. Prior to this users were stuck in this cycle for hours.
  • 37. Citrix User Filer Access Error Details
  • 38. Blind vs. Pinpoint Upgrades Blind Upgrade = Shotgun Approach = Forklift Upgrade
  • 39. Root Cause Optimization Definitive Root Cause Analysis Pinpoint Cause Measure ROI Potential Pinpoint Purchases Validate & Prove ROI Award Innovation Optimization Root Cause Analysis
  • 40. IT Critical Problem Resolution Technology and Psychology [email protected]