Skip to main content
The Dark Art of Postmortem DebuggingRead
Wi-Fi & access points · A-01

The client that keeps dropping is a hardware address until a second file says whose it is.

WARD 3AWARD 3BWARD 3CCORRIDORNURSE STATIONMEDSAP-01AP-0202:00:00:00:00:0102:00:00:00:00:0202:00:00:00:00:0302:00:00:00:00:0602:00:00:00:00:0502:00:00:00:00:0902:00:00:00:00:04
02:00:00:00:00:04· in the log
Handset, nurse pool 3B
client table · 2nd file in archive
31 drops / 7 d · reason code 3
The association log names this client by hardware address, the client table in the same archive names it by device, and the join between the two files is drawn for you.
Sheet
A-01
Scale
1 dot = 1 client
Data
Illustrative. Synthetic data.
client
access point
association
kept dropping
What to upload
ABCDEFG1234WARD 3AWARD 3BWARD 3CSTAIRCORRIDORPRINT ROOMSTOREOFFICEW.C.DAY ROOMNURSE STATIONMEDSAP-01 · 5 GHz · CH 36AP-02 · 5 GHz · CH 44AP-03 · 2.4 GHz · CH 602:00:00:00:00:0102:00:00:00:00:0202:00:00:00:00:0302:00:00:00:00:0502:00:00:00:00:0602:00:00:00:00:0702:00:00:00:00:0802:00:00:00:00:0902:00:00:00:00:0A02:00:00:00:00:0B02:00:00:00:00:0C02:00:00:00:00:0F02:00:00:00:00:0D02:00:00:00:00:0EN
Wi-Fi & access points · sheet A-01 · floor 3

The client that keeps dropping is a hardware address until a second file says whose it is.

02:00:00:00:00:04· in the log
Handset, nurse pool 3B
client table · 2nd file in archive
31 drops / 7 d · reason code 3
The association log names this client by hardware address, the client table in the same archive names it by device, and the join between the two files is drawn for you.
Sheet
A-01
Scale
1 dot = 1 client
Data
Illustrative. Synthetic data.
client
access point
association
kept dropping
What to upload
What comes back
sheet A-02 · Wi-Fi & access points

Clients with names, ranked by what they did.

Charts no single file in the archive could produce. The floor from sheet A-01, read as a schedule.

Client schedule · sorted by drops, not joins
Mark
Address (log)
Resolved (client table)
Type
OS
Drops 7d
Joins 7d
04
02:00:00:00:00:04
Handset, nurse pool 3B
handset
Android
31
212
0B
02:00:00:00:00:0B
Label printer, print room
printer
embedded
9
14
07
02:00:00:00:00:07
Laptop, visitor (stair)
laptop
Windows
6
40
01
02:00:00:00:00:01
Handset, nurse pool 3A
handset
Android
3
168
09
02:00:00:00:00:09
Workstation, nurse station
desktop
Windows
2
3
0F
02:00:00:00:00:0F
unidentified, not in the client table
.
.
1
4
0D
02:00:00:00:00:0D
Tablet, day room
tablet
Android
0
88
0C
02:00:00:00:00:0C
Laptop, office
laptop
Windows
0
22
1Clients resolved to devices

Hardware addresses are matched against the fingerprint table in the same upload. A candidate that resolves nothing is not used, so what you see are real matches rather than a guess.

2Ranked by instability

Clients ordered by how often they dropped rather than how often they connected. The device with a problem sorts to the top instead of the device that is simply busiest.

3Split by device type and OS

Connections grouped by what kind of device made them and what they were running, so a fault that only affects one fleet or one platform is visible as a shape rather than a hunch.

By type
handset
6
laptop
3
printer
2
desktop
1
tablet
1
unidentified
1
By OS
Android
7
Windows
4
embedded
2
unidentified
1
4Ask it directly

Point a question at the archive in plain language and get a cited answer.

Which clients dropped between 02:00 and 03:00 on Tuesday, and on which band?
02:00:00:00:00:04 (Handset, nurse pool 3B): 6 drops, reason 3, on 5 GHz via AP-01. No other client dropped in that hour.
cited · access point log 4102 to 4118 · radio config radio0
Illustrative. Synthetic data.
Why it is hard
sheet A-03 · Wi-Fi & access points

Wi-Fi problems are spread across files that do not reference each other.

Each file is readable. The answer is in the relationship between them.

Association log1 / 3
12:03:41 AP-01 STA 02:00:00:00:00:01 associated
12:03:58 AP-01 STA 02:00:00:00:00:04 associated
12:07:12 AP-01 STA 02:00:00:00:00:04 disassoc reason=3
12:07:15 AP-02 STA 02:00:00:00:00:04 associated
12:09:02 AP-01 STA 02:00:00:00:00:0B associated
12:11:40 AP-02 STA 02:00:00:00:00:04 disassoc reason=3
12:11:44 AP-01 STA 02:00:00:00:00:04 associated
12:14:09 AP-02 STA 02:00:00:00:00:07 authenticated
12:15:30 AP-01 STA 02:00:00:00:00:0F associated
12:18:51 AP-01 STA 02:00:00:00:00:04 disassoc reason=3
... 61,204 more lines this week
Radio config2 / 3
wireless.radio0.band='5g'
wireless.radio0.channel='36'
wireless.radio0.htmode='VHT80'
wireless.radio0.disabled='0'
wireless.ap0.ssid='[network name]'
wireless.ap0.disassoc_low_ack='1'
wireless.ap0.bss_transition='1'
wireless.radio1.band='2g'
wireless.radio1.channel='6'
wireless.radio1.disabled='0'
(no client named anywhere in this file)
Client table3 / 3
address type os name
02:00:00:00:00:01 handset Android Nurse pool 3A
02:00:00:00:00:04 handset Android Nurse pool 3B
02:00:00:00:00:07 laptop Windows Visitor
02:00:00:00:00:09 desktop Windows Nurse station
02:00:00:00:00:0B printer embedded Print room
02:00:00:00:00:0C laptop Windows Office
02:00:00:00:00:0D tablet Android Day room
02:00:00:00:00:0E handset Android Day room
(02:00:00:00:00:0F is not here)
(no timestamps, no radios in this file)
the join nobody makes by hand: it passes behind the config sheet, which has never heard of the client
Every client is an opaque address

An association log is a list of hardware addresses joining and leaving. Which of them is the handset a nurse carries, and which is a printer nobody has touched in a year, is not in that file.

The radio config is somewhere else

What band a client was on, what the retry and steering settings were, whether the network was even advertising at the time: all in configuration files sitting beside the log, in a different format.

Disconnects are normal until they are not

A busy access point logs thousands of joins and leaves a day. Picking the one client whose pattern changed means counting, and counting by hand across a week of logs is nobody's job.

Three sheets from one archive. Illustrative. Synthetic data.
What to upload
sheet A-04 · Wi-Fi & access points

Put the access point's files in one archive.

The relationships are worked out from the contents. One archive, four kinds of sheet; only the first is required.

A-01
Access point logs

Association and authentication daemon output: clients joining, leaving, failing to authenticate, and the reason codes that came with it.

required
A-02
Radio and router config

Access point configuration and router settings are recognised as configuration rather than prose, so what the radio was set to is read alongside what it did.

optional
A-03
Client fingerprint database

A table mapping hardware addresses to device names, types and operating systems. This is the file that turns the log into something you can read.

optional, resolves names
A-04
Packet captures

A capture taken on the same network is read as structured records: protocols, conversations, and the exchanges behind a failed association.

optional
the join on sheet A-01 needs A-01 and A-03 in the same archive
How this reaches you
sheet A-05 · Wi-Fi & access points

Three situations an access point archive turns up in.

And what the join gives you in each. The same floor from sheet A-01, three times.

AP-01AP-02ONE FLOOR, ONE RADIO: 4 OF 5 HANDSETS ON AP-01 DROP
A fleet that keeps dropping in one building

Handsets losing the network in a way nobody can reproduce on demand. The clients are resolved to real devices, ranked by disconnects, so you can see whether it is one model, one floor, or one radio.

HANDSET 6LAPTOP 3PRINTER 2UNIDENTIFIED 1
Who is actually on this network

An association log read as a device population rather than a list of addresses, split by type and operating system, with anything the fingerprint table cannot identify reported as unidentified rather than quietly dropped.

BEFORE · 1 OF 6AFTER · 4 OF 6DELTA
It got worse after a change

Upload the archive from before and the one from after. The comparison, Delta, names what differs between them on one shared clock, rather than leaving you to diff two directories by eye.

Illustrative. Synthetic data.
General notes
sheet A-06 · Wi-Fi & access points

What this is not.

This reads the files an access point and its network produce: logs, configuration, client tables and captures. It is not a radio survey, a spectrum analyzer or a live monitoring agent, and it does not measure signal quality it was never given. If the answer is not in the files you uploaded, it will say so rather than infer it.

Not on this sheet
Radio survey
Spectrum analyzer
Live monitoring agent
Signal quality it was never given
If it is not in the files, it says so.
Analyzers for the network stack
sheet A-07 · Wi-Fi & access points
SEE A-11
PCAP Analyzer

802.11, TCP, and DNS forensics from a packet capture.

SEE A-12
Bundle Analysis

Cross-file correlation across a whole diagnostic archive.

SEE A-13
Dmesg Analyzer

Kernel panics, oopses, and driver faults from dmesg.

SEE A-14
Logcat Analyzer

Root cause from a raw logcat stream, cited to the line.

Frequently asked questions
sheet A-08 · Wi-Fi & access points

Frequently Asked Questions

Q-01
What do I actually need to upload?

At minimum the access point's log. Add the client fingerprint table and the resolution from hardware address to device name becomes possible; add the radio configuration and what the access point was set to is read alongside what it did. Put them in one archive and upload that.

Q-02
What if I have no fingerprint table?

The logs are still read, counted and searchable, and the clients stay as hardware addresses. Nothing is invented to fill the gap, and the analysis says which clients it could not identify.

Q-03
Does this work with OpenWrt?

Yes. Router configuration in that style is recognised as configuration rather than read as prose, so it is used as context for the logs beside it.

Q-04
Can it tell me why a client roamed?

It can tell you what the logs recorded: when the client left, what reason code came with it, and what the access point was configured to do. It cannot tell you what the radio environment was doing, because that is not in the files.

Q-05
Is my log data secure?

Your log data is encrypted in transit (TLS 1.3) and at rest (AES-256), processed in your own tenant, and never used to train AI models. See the architecture page for where data goes and what leaves your environment. Files are deleted after 90 days, or immediately from your dashboard. Enterprise plans offer on-premise deployment for regulated or air-gapped environments.

Sheet A-09 · title block

Bring us an access point archive.

Logs, config and the client table from one site. From there we will scope a pilot for your team.

Contents
A-01 access point log
A-02 radio and router config
A-03 client fingerprint table
A-04 packet captures
Site
one, any floor
Runs
our cloud, your cloud, or on premises