Session list¶
Every request Quena records is a session: the request, the response (if any), timing, the client process and your own notes. The list handles hundreds of thousands of sessions.
Columns¶
| Column | Shows |
|---|---|
# |
Session number, in arrival order. |
| Method | HTTP method as a coloured badge. |
| Status | Response status as a coloured badge (ERR for an aborted session without a status). |
| Host | Target host. Tunnels are listed by their target host with a badge. |
| Path | Path and query. Takes the width the other columns leave. |
| Type | Response Content-Type. |
| Size | Response body size in bytes. |
| Duration | Time from request to complete response. |
| Process | The application that sent the request. |
| Protocol | Protocol of the session (e.g. HTTP, HTTPS). |
| Comments | Your comment, or one a rule or script added. |
| Custom | A value from the rules script (Quena.registerColumn). |
| Caching | Caching-related response headers. |
| Started | Time the request started. |
The Quena layout shows #, Method, Status, Host, Path, Type, Size and Duration; the Classic
layout shows more columns.
- Sort: click a column heading (ascending, descending, back to arrival order).
- Show or hide columns: right-click the heading row. Reset Columns restores the layout's defaults.
- Resize by dragging the edge of a heading, reorder by dragging a heading onto another.
Grouping¶
Group by (right-click the heading row, or the command palette) keeps sessions that belong together in one block:
| Group by | Sessions that share |
|---|---|
| Connection (keep-alive) | the client connection: requests a browser sent over one keep-alive or HTTP/2 connection |
| Host | the target host |
| Process | the client application |
| Trace / correlation id | the trace id (traceparent, B3, uber-trace-id, X-Amzn-Trace-Id, X-Cloud-Trace-Context) or a correlation header (X-Correlation-ID …) — one user action across connections |
| Session cookie | the session cookie (JSESSIONID, PHPSESSID, ASP.NET_SessionId, connect.sid, sessionid …) — one login |
| Custom column | the value a rules script puts into Custom: your own grouping |
- Groups appear in the order of their first session; inside each group the list is
sorted by the column you click. With
#descending, the newest groups come first. - The Group column shows, on each group's first row, what the sessions share and how many there are; a coloured bar marks the group. Sessions without a key (no trace id, no session cookie …) stay single rows.
- Collapse a group by clicking ▾ in its Group cell, or with
←on one of its rows;→or ▸ expands it. A collapsed group shows its first session. Collapse all groups / Expand all groups in the same menu. Right-click a session → Group → Select group selects all of it. - New traffic joins its group while capturing. Filters apply first: a group counts its sessions that pass the filter.
- The session cookie's value is never shown or stored in the list: equal values give equal groups, the label shows the cookie name and a short hash.
The filter fields conn, trace and session select the same sessions, e.g.
conn == 1825362123456 or trace == 4bf92f3577b34da6a3ce929d0e0e4736 (see
syntax).
Colours¶
The list is meant to be read at a glance:
| What | Colour |
|---|---|
| Status badge | 2xx green, 3xx muted, 4xx amber, 5xx red, 1xx blue |
| Method badge | GET blue, POST green, PUT/PATCH amber, DELETE red, CONNECT/HEAD/OPTIONS muted, others violet |
| Duration | amber above 1 s, red above 5 s |
| Size | amber above 1 MB, red above 10 MB |
| Row text | red for aborted sessions, grey for tunnels, italic while still in flight |
| Row paused at a breakpoint | bold red on a red background |
| Your marks | the row gets the mark's background colour, in bold |
A thin state bar at the left edge of a row shows red for a breakpoint or an aborted session, the accent colour while the session is in flight, purple for a response from Mock Rules and blue for a WebSocket.
Selecting¶
- Click,
Shift+click andCtrl/⌘+click select as usual;Ctrl/⌘ Aselects all. - Arrow keys,
Page Up/Page Down,Home/Endmove the focus (withShiftto extend). Enteror a double-click opens Inspect;Escclears the selection.- Right-click → Select → Same Host / Same Process / Duplicate Requests.
- The command field selects by text, host, status and more (see below).
The status bar shows how many sessions are selected, visible and recorded in total.
Marks and comments¶
- Mark sessions with
Ctrl/⌘ 1…6(red, blue, gold, green, orange, purple);Ctrl/⌘ 0removes the mark. Also in Edit → Mark and the context menu. - Comment with
M(or the toolbar speech-bubble button, Edit → Comment…). The text appears in the Comments column. Several selected sessions get the same comment.
Marks and comments are saved in .saz archives, and both can be used in filters
(color == red, comment ~ todo).
Removing sessions¶
| Action | Key |
|---|---|
| Remove selected | Del (or Backspace) |
| Remove all except the selected | Shift Del |
| Remove all | Ctrl X (also ⌘X on macOS), or cls in the command field |
The toolbar's Remove button also removes all Images, Tunnels (CONNECT), Non-200s, or Complete & Unmarked sessions at once.
Command field¶
The command field in the middle of the toolbar (Alt Q, or / while the list has focus)
selects sessions and runs commands. ↑/↓ walk through the history, Esc returns to the
list, and help shows the syntax.
?login select sessions whose URL contains "login"
@github.com select sessions for a host
=500 select by status code (or =POST for a method)
>100k <5k select by response size
select json select by content type
filter status >= 400 hide everything else (filter alone removes it)
keeponly image remove sessions whose content type does not match
tail 1000 keep only the 1000 most recent sessions
cls remove all sessions
bpu /api break before requests whose URL contains /api
bpafter /api break after responses whose URL contains /api
bps 500 break on responses with status 500
bpv POST break on a request method (also bpm)
g resume all paused sessions
dump save all sessions as a .saz archive
start | stop start or stop capturing
The full list, including the expressions filter understands, is in
Command and filter syntax.
Command palette¶
Ctrl/⌘ K (or View → Command Palette…) opens a searchable list of every command —
capture, breakpoints, archives, copying, views, tools and help — with its shortcut. Type a
few letters, pick with the arrow keys and press Enter.
Find¶
Find Sessions (Ctrl/⌘ F, Edit → Find Sessions…, or the magnifier in the toolbar)
searches the content of sessions, not only the list:
| Option | Choices |
|---|---|
| Search | requests and responses, requests only, responses only, URLs only |
| Examine | headers and bodies, headers only, bodies only |
| Result highlight | mark hits in a colour (gold by default), or only select them |
| Checkboxes | Match case, Regular expression, Decode compressed bodies, Selected sessions only |
| Skip bodies larger than (MB) | default 64 |
The search runs as a background job with progress; hits are selected when it finishes.
Filters¶
The Filters tab hides sessions from the list (they are still recorded). Check Use Filters; changes apply immediately. Reset clears everything.
| Section | Options |
|---|---|
| Hosts | no host filter, Show only or Hide the listed hosts (*.company.de; localhost) |
| Client Process | all processes, browsers, non-browsers, remote clients; Show only traffic from, Hide traffic from |
| Request Headers | Show only if URL contains, Hide if URL contains, Hide CONNECT tunnels |
| Response Status Code | hide 2xx, non-2xx, 401/407, redirects, 304 |
| Response Type and Size | hide images, CSS, scripts, fonts; show only / hide content types; hide smaller/larger than (KB); hide faster than (ms) |
| Advanced expression | a filter expression, e.g. host ~= "*.company.de" and method == POST and status >= 400 |
Quick ways to filter:
- Right-click a session → Filter Now → Hide this Host / Show only this Host / Hide this URL / Hide this Process / Show only this Process.
- View → Hide in List → Tunnels (CONNECT) / Image Requests / 304 Not Modified.
filter <expression>in the command field.
While a filter is active, the Filters tab shows a dot and the status bar says filtered.
Keep and tail¶
To stop a long capture from growing without end:
- The toolbar Keep button keeps only the newest 100 … 10,000 sessions continuously.
tail 1000in the command field trims the list once to the newest 1,000.keeponly jsonremoves everything that is not JSON.
Log¶
The Log tab shows Quena's own log messages — the first place to look when something does not work as expected.