Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Best way to track traffic

Status
Not open for further replies.

cyberkatis

IS-IT--Management
May 30, 2002
29
0
0
US
If I have MRTG running and notice a huge rise in outgoing traffic during the night hours and I want to find out all about it (Source, Destination at least) what is the best way to handle this.

1) Sniffer-
Currently using Netmon and Ethereal, but the buffers get filled up too fast to run all night. Any ideas here?

2) Something else?

Thanks

Chris.
 
Sniffer will track the top 10 talkers and once you know that, you build a filter set to knock out the extra noise.

Solarwinds also does this in a nicer and easier to read report by using SNMP. Tag the servers and routers and you can build a map of what is being excessively used. I have found *hidden* backups kicking off this way and a few other surprises.


MikeS
Find me at
"Take advantage of the enemy's unreadiness, make your way by unexpected routes, and attack unguarded spots."
Sun Tzu
 
Hi Chris,

Since you're only after the source and destination addresses (for now), limit the packet size in Ethereal. Start with small packets (<100 bytes). Once you have a better idea, filter on specific IP addresses and capture full packets to determine the nature of the traffic.

J.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top