FAQ

Frequently asked questions

Short answers, including the ones where the answer is no.

Install and driver

Does CommMonitor take the COM port away from my application?

No. The bundled kernel driver attaches a filter to the serial device stack, and your application keeps the port handle. That is the difference between this product and a monitor that has to open the port first.

Do I need administrator rights?

You need administrator rights to install or start the kernel driver. Capturing traffic afterwards does not need elevation.

Can I uninstall the driver?

There is no uninstall action, and that is deliberate. A filter driver that is already sitting in a device stack can leave the device in an undefined state if it is stopped underneath a running application. The installer also leaves an existing driver file of the same name alone.

Which Windows versions are supported?

Windows 10 and Windows 11, 64-bit. Windows 7 x64 is not declared as supported at this time: capture on that platform has not been verified and a driver-level error has been observed there.

Capture

What can the driver actually see?

The requests that pass through the monitored ports. The filter is configured per port with a bitmap of 39 serial control codes and 28 IRP major function codes, 67 entries in total.

Can it capture a port that is already open?

Yes. Because the filter is attached at the driver level, a port that your own software has already opened is exactly the case it is built for.

What happens if no traffic is captured?

The view shows a waiting state rather than an error. Frames appear the moment the device talks, and the Problems panel reports driver or port errors separately.

Protocols

Which protocols are decoded?

Modbus RTU, Modbus ASCII, DL/T 645, IEC 60870-5-101, NMEA 0183 and AT command traffic. Two things are worth separating: the views are always there, the decoded values are not. Protocol and Modbus analysis is a Professional feature - in the free, trial and standard editions those views show the same frames with every decoded value replaced by ****. In the Professional edition the decoded fields appear next to the raw bytes, and the plugins can be enabled, disabled and reordered in Settings.

Can it decode a proprietary protocol?

Not in this release: the protocol set is the one that ships with the build. If your protocol matters to you, tell us what it is - that is how the list grows.

Export and redirect

Which export formats are available?

Two different jobs. The visible view is saved as a snapshot — ANSI text, Unicode text, HTML or CSV — with exactly the rows and columns you see on screen and no row limit on a full licence; this snapshot export comes with Standard. The whole frame pool is exported regardless of filters as JSON Lines (one object per frame) or PCAP (little-endian, link type 147, so Wireshark shows the raw bytes); this frame-pool export is the only export reserved for Professional. Default file names are the session name plus the view name in English, for example COM7_Table.csv or COM7_Table.pcap.

How does redirect to a file work?

New rows of the active view are appended to a file, flushed every five seconds or as soon as the buffer reaches 256 KB. Files can be split by time range or by size, and a single file stops at 1 GB.

How does forwarding to TCP or HTTP work?

Frames are batched, up to 100 per batch, and sent as a 4-byte big-endian length prefix followed by a UTF-8 JSON array. TCP is the primary channel and HTTP is the fallback; the HTTP path posts to /batch.

Sessions and dashboard

What is a .cms file?

A session file holding a whole capture. When you protect it with a password the payload is encrypted with AES-256-GCM using a key derived with PBKDF2-SHA256; without a password the file falls back to the older obfuscation, and the header records which one was used. Sessions written by older versions can still be opened.

Is the dashboard reachable from the network?

No. It binds to 127.0.0.1 on port 5000 only, answers read-only GET requests, and the page polls once a second. It is a convenience view for the machine it runs on, not a shared service.

Licensing

What can I do without a licence key?

Without a key the application still captures: driver-level capture on any COM port and the four base views (Table, Hex Dump, Line and Terminal). Export, the local dashboard, redirect, forwarding and protocol decoding need a licence - the trial edition adds the dashboard, a row-capped CSV export and forwarding whose frame data is masked. There is no countdown, so nothing stops working after a set number of days.

Can I activate a machine with no Internet connection?

Yes. Generate an offline request file, send it to us, and import the signed licence we return. Both directions are command-line operations.

Will the licence stop working while a machine is offline?

A perpetual licence is not affected by time. A subscription licence keeps working offline for a grace period of 30 days by default, unless the licence states another number, and then asks for a connection once so it can be validated again.

The licence says it does not match this machine. What now?

Licences are bound to hardware identifiers collected in a fixed order: motherboard UUID, system disk serial, physical MAC address, and the Windows machine GUID. If you replaced a component, send us the fingerprint from the new machine and we re-issue the licence.

Performance and limits

What frame rate can it handle?

We do not publish a frame-rate figure, because any number depends on the machine, the driver path and the payload. The product ships throughput and capture probes for exactly this reason; if you tell us your hardware and traffic shape, we will measure it with you instead of quoting a marketing number.

Is there a limit on how long a session can run?

No time limit is imposed. The frame pool and the view refresh are throttled so that long captures stay responsive, and stopping a capture keeps the existing pool instead of discarding it.

Question not answered here?

Send it to the address in the footer. If the answer is useful to everyone, it ends up on this page.