Introduction
This article explains how to deploy Sensor Capture Virtual Appliance in Hyper-V.
Basic Principles
North to South Visibility
- 100% user activities covered
- 100% applications analyzed
- Long look back retention
- Performance baselines
- L2 to application transactions
- Automated analysis
East to West Visibility
- Addresses both infrastructure and application requirements
- Non-intrusive virtualized datacenter integration
- Full application-chain insight across hybrid clouds & SDNs
- Fast time to value
- Low TCO
Why is Sensor Capture better for E/W visibility than other NPMD technologies?
Sensor Capture leverages its pure software sniffer to deliver agentless performance management in virtualized and cloud environments.
Others relying on hardware components offer intrusive alternatives requiring NICs, Network Packet Brokers (NPB), and generate additional traffic load.
Hyper-V Traffic Mirroring Capabilities
Hyper-V vs VMware virtual switching capabilities:
-
Virtual switching can only be configured on a per-host basis.
-
Virtual switching on host-basis or Virtual distributed switching on a global level.
Hyper-V Virtual Switch Deployment Models
Three deployment models of Hyper-V Virtual Switches
| External Virtual Switch | Internal Virtual Switch | Private Virtual Switch |
|---|---|---|
|
|
|
Single Host Hyper-V Virtual Switch Configuration
A Virtual Switch is a host-based configuration:
Multiple Host Hyper-V traffic Capture Designs
No ERSPAN capabilities like in VMware: the virtual switch can't send a copy of traffic via ERSPAN encapsulation.
Hyper-V only supports intra-VMs traffic monitoring within the same Hyper-V host (due to the lack of VMware VDS alike switching capabilities):
If you need to monitor intra-VMs traffic in a Hyper-V host on which there is no Sensor Capture VA running, a third-party tool that can encapsulate a copy of the traffic of interest into GRE/ERSPAN or HP ERM should be used.
This kind of mirroring protocol relies on a flow that can be routed to the capture (on which a network interface should have an ip address)
Physical Network Traffic Monitoring
SPAN/RSPAN
Capturing traffic from the physical network to Hyper-V is not supported.
GRE/ERSPAN/HP ERM encapsulation
Capturing traffic from physical network to a VM in Hyper-V is possible via GRE/ERSPAN encapsulation or HP ERM encapsulation.
Tested Hyper-V Platforms
Platforms that have been successfully tested and validated:
- Windows 2012 Server
- Windows 2016 Server
- Windows 2018 Server (1803)
How to Install Sensor Capture in a Hyper-V Environment
Hyper-V Manager is the tool being used.
To install Sensor Capture in a Hyper-V environment
-
Right-click on the Hyper-V host.
-
Select Import Virtual Machine... from the drop-down menu.

-
In the Before You Begin step, click Next >.
-
In the Locate Folder step, click Browse. The Sensor Capture Hyper-V software image is composed of three folders.
-
Select the folder with the three subfolders called Snapshots, Virtual Hard Disks and Virtual Machines inside it.
-
Click Select Folder.

-
Click Next >.

-
In the Select Virtual Machine step, select your VM and click Next >.

-
In the Choose Import Type step, select the Copy the virtual machine (create a new unique ID) radio button.
-
Click Next >.

-
In the Choose Destination step, change the virtual machine storage location (if needed) and click Next >.

-
In the Choose Storage Folders step, select the folder to store the Virtual Hard Disk and click Next >.

-
In the Connect Network step, select the external vSwitch that you will use to acccess the Sensor Capture Web UI. By default, the Sensor Capture image looks for a vSwitch called 'admin' to link its administration interface.
-
Click Next >.

-
Select the internal vSwitch you'll use to capture intra-VMs traffic. By default, the Sensor Capture image looks for a vSwitch called 'mirror' to link its capture interface.
-
Click Next >.

-
Review from the Summary step and click Finish once done.

- Once deployed, right-click on the virtual machine name and select Rename... in the drop-down menu.

- Click Start by either right-clicking on the Sensor Capture virtual machine or by using the Actions menu.

How to Add Sniffing Interfaces to the Sensor Capture Virtual Appliance
To add sniffing interfaces to the Sensor Capture virtual appliance
-
Right-click on the Sensor Capture virtual appliance virtual machine and select Settings... in the drop-down menu.

-
In the dialog box, select Add Hardware.
-
Select Network Adapter.
-
Click Add.

-
Choose the Virtual Switch you want to attach the new virtual network adapter to.
-
Click Apply.

How to Configure a Hyper-V Virtual Switch
To configure a Hyper-V Virtual Switch
-
Click on the Hyper-V host.
-
Select Virtual Switch Manager... in the Actions menu.

-
Select the vSwitch type to create.
-
Click Create Virtual Switch.

-
Provide a name for the vSwitch.
-
Add notes if needed.
-
Select the Hyper-V host physical network adapter to attach to this external vSwitch.
-
Click OK.

-
Click Yes once the pop-up window appears.

- The external vSwitch has now been successfully created.

- Refer to the Internal network radio button, the procedure is identical for internal vSwitches except that you do not link any physical network adapter.

How to Configure Port Mirroring
Configuring the mirroring on the monitored virtual machines
To configure port mirroring
-
Right-click on the virtual machine and select Settings... in the drop-down menu.

-
Select the Network Adapter and Advanced Features menu.
-
Select Source in order to capture the virtual machine corresponding traffic.
-
Click OK.

Configuring the Sensor Capture virtual appliance mirror interface as the traffic destination
** To configure the Sensor Capture virtual appliance mirror interface as the traffic destination**
- Select the Sensor Capture virtual appliance virtual machine.
- Select the sniffing interface.
- Select the Destination for the captured traffic.
- Click OK.

© 2026 Cisco and/or its affiliates. All rights reserved.
For more information about trademarks, please visit: Cisco trademarks
For more information about legal terms, please visit: Cisco legal terms