See what your BACnet network is actually doing
Upload a BACnet packet capture and get an automated analysis: an overall rating, the devices on the wire, and the problems worth fixing first. Free, in your browser, with no account to create and nothing to install.
Analyze a capture
Drop a BACnet packet capture below, add your work email, and we will analyze it.
Reading the capture
Decoding the BACnet packets in your file.
Network analysis report
Health by category
Topology summary
Findings
Device inventory
Data exchanges
Packets
Decoded BACnet packets from this capture. Click a row to expand its full decode.
See how BACsync BSP-1000 prevents these problems across your sites
One platform that keeps every site healthy, synchronized, and observable, without the issues this report surfaced.
Request a walkthroughReading the report, and its limits
Passive capture analysis is a fast, no-touch way to spot trouble, but it is an indicator, not a verdict. The result depends on when, where, and how you captured. Here is what that means and how to get the most accurate result.
What does the rating mean?
The rating is a word, not a mark. It is derived from one network model built from your capture, in two steps.
First the capture vantage decides whether device health can be judged at all. A thin, broadcast-only or one-sided capture is reported as Limited, because the replies that would prove a device healthy never reached the capture point. We would rather say "not assessable from here" than award a confident pass.
When the vantage genuinely sees both directions, the rating follows the findings: a serious fault rates at most Degraded, lesser issues cap at Acceptable, and a capture with nothing found reads Healthy. Treat it as a triage signal for this capture, not a certificate for the whole system.
Either way it describes this capture, not the whole system. That is the honest limit of passive analysis, and the reason every report also states what the capture point could and could not see.
Why can two captures of the same network be rated differently?
Because they saw different traffic. Time of day changes what is happening (overnight schedules, morning startup, trend uploads). Capture location changes what reaches your NIC. Duration changes whether intermittent problems appear at all. The network did not change; your view of it did.
Why does the capture method matter so much?
You can only analyze packets that reached the capture point. Three common setups see very different things:
- Mirrored / SPAN port or TAP at the BBMD or main router: the best view. You see broadcast and the unicast polling between devices.
- A plain switch port (no mirroring): you mostly see broadcast traffic (Who-Is, I-Am, COV broadcasts). Device-to-device polling is invisible, so read-rate, response-time, and error checks are limited.
- On a busy workstation or controller NIC: you see that one device's traffic, not the segment's.
If the report says traffic is almost all broadcast, that is usually a mirroring gap, not a quiet network.
How long should I capture?
Ten to thirty minutes is a good default. A 30-second snapshot can miss periodic events entirely: token loss on an MS/TP trunk, a slow nightly schedule, hourly trend reads, a router that only misbehaves under load. Longer is better, up to the upload limit shown on the upload panel (larger limits are available on request, and the desktop tool has none). If a capture is larger than that, narrow it with a BACnet capture filter rather than shortening the time window.
Why "not observed" instead of "not present"?
Absence of evidence is not evidence of absence. If we did not see MS/TP frames, we say MS/TP was not assessed, not that your trunks are healthy. If we did not see a device respond, we do not assume it is offline. We only flag what the capture actually shows, and we tell you what it could not reach.
Tips for a capture that gives accurate results
- Capture at or near the BBMD or the segment's main router.
- Use a mirrored (SPAN) switch port or an inline TAP, not a plain access port.
- Run it for 10 to 30 minutes during normal operation.
- Include a Who-Is / I-Am cycle so device discovery is represented.
- Capture per broadcast domain: one capture per BACnet/IP subnet tells a cleaner story than one mixed file.
- Export as .pcap or .pcapng (Wireshark, tcpdump, or your BAS tool's capture export).
Is my capture file stored?
No. The file is analyzed in memory and deleted as soon as the report is generated. We keep the summary needed to show you this report, never the raw packets. Your email is used only to send you the result and BACsync updates.