09-22-2007
Quote:
Originally Posted by
mansoorulhaq
I want to monitor network traffic. For this purpose i use snoop command. But snoop command only show those packets which are broadcasted or those packets which recieved by host. But I want to examine whole network traffic. Please tell me how to use snoop for monitoring whole network traffic or if there is any other command/tool for monitoring network traffic.
I have done a similar kind of self interest project a couple of years ago for dynamic port allocation and abuse message filter; but not exactly of the same kind
You could try something like,
listener binded as raw socket to the network interface and since the entire traffic needs to be monitored. A central node which act as the intermediate hop station routing packets from one node to other node.
With the socket to the network interface of the router you should be able to monitor the traffic.
This is just a heads up, may not be even applicable to the project that you are trying to do !
10 More Discussions You Might Find Interesting
1. UNIX for Dummies Questions & Answers
there are commands to monitor the memory, paging, io... how about network traffic. i mean commands to see whether the network traffic (LAN) is congested? the closest i got is netstat
thanks (6 Replies)
Discussion started by: yls177
6 Replies
2. Cybersecurity
Hi,
Can someone give me the clue on how to capture network traffic at gateway.
Thanx (2 Replies)
Discussion started by: kayode
2 Replies
3. Infrastructure Monitoring
Hi all,
Got a strange one here, well not so much strange, different :-)
I need to work out if a server is particulary chatty, whether its talking / communicating heavily to a particular server, as Im planning to physically move the server to a different server, over a link. Hence the... (6 Replies)
Discussion started by: sbk1972
6 Replies
4. UNIX for Dummies Questions & Answers
Folks;
I have 2 NIC cards on my SUSE Linux server. One of them was reporting receive errors for a while now it's OK, but i'd like to monitor it.
Is there any command i can run to tell me the usage in the past or give me a history of traffic and the speed that going on this specific card?
I... (1 Reply)
Discussion started by: Katkota
1 Replies
5. Cybersecurity
Hi all,
How can I monitor packet traffic on my wireless router?
Some info
- my wireless router is netgear wgr614
- everyone can connect it i.e. no password required
- I would like to see where they connect, how they are using the internet connection
I installed wireshark and captured... (3 Replies)
Discussion started by: SaTYR
3 Replies
6. HP-UX
I Colleagues,
Somebody can say me how to monitoring traffic in the network. also I am interested in monitoring memory. if somebody to know a guide with command advanced in unix welcome for me.
Thank you for adcanced. (0 Replies)
Discussion started by: systemoper
0 Replies
7. Shell Programming and Scripting
Hello All,
I have written a script to check for http error code 500 in the logs.
here is the code
#!/bin/bash
#########################################################################################################
# Shellscript : trafficchk.sh -Traffic Monitoring
# Version ... (3 Replies)
Discussion started by: Siddheshk
3 Replies
8. Infrastructure Monitoring
If I would like to know what connection , data , traffic in a network port ( eth0 ) , what can I do ?
ps. because I always found the network is very slow , so I would like what the network port is doing .
Thanks
Login ID ust3 is currently in read-only mode for multiple infractions. Creating... (0 Replies)
Discussion started by: ust03
0 Replies
9. UNIX for Advanced & Expert Users
Hi All
I am resilience testing an application that is spread across multiple servers.
One thing I will need to do soon is throttle the network traffic for specific interfaces within the test cluster. Specifically, maybe make a connection take twice or three times as long to respond....
I... (3 Replies)
Discussion started by: bbq
3 Replies
10. IP Networking
My son does homework on a school laptop. I was thinking about setting up a gateway on my home network, so that I can monitor web traffic and know if he is doing his homework without standing over his shoulder. Ideally I would like to use the Raspberry Pi Model b that I already have. However, I... (15 Replies)
Discussion started by: gandolf989
15 Replies
LEARN ABOUT ULTRIX
ruptime
ruptime(1c) ruptime(1c)
Name
ruptime - show host status of local machines
Syntax
ruptime [ options ] [ machinename ]
Description
The command gives a status line like for each machine on the local network. If a machinename is given, the status of only the named
machine is given. These status lines are formed from packets broadcast by each host on the network once a minute.
Machines for which no status report has been received for 5 minutes are shown as being down.
Options
-a Users idle an hour or more are not counted unless this option is specified.
-d Display only those hosts that are considered down.
-l Sort the status list by load average. If more than one sort option is given, uses the last one.
-r Show only hosts that are up and running.
-t Sort the status list by uptime. If more than one sort option is given, uses the last one.
-u Sort the status list by number of users. If more than one sort option is given, uses the last one.
-nn Show only those hosts with nn or more users.
Restrictions
Because the daemon sends its information in broadcast packets it generates a large amount of network traffic. On large networks the extra
traffic may be objectionable. Therefore, the daemon is disabled by default. To make use of the daemon for both the local and remote
hosts, remove the comment symbols (#) from in front of the lines specifying in the file.
If the daemon is not running on a remote machine, the machine may incorrectly appear to be down when you use the command to determine its
status. See the reference page for more information.
If a system has more than 40 users logged in at once, the number of users displayed by the command is incorrect. Users who login to a
machine after that point fail to increment the user count that appears in the output of the command. This is due to the maximum size limit
of an Ethernet packet, which is 1500 bytes, and the fact that the daemon must broadcast its information in a single packet.
Files
/usr/spool/rwho/whod.* Information about other machines
See Also
rwho(1c), rwhod(8c)
ruptime(1c)