Security Basics mailing list archives

Re: using promiscuous mode to tabulate network statistics


From: Tremaine Lea <tremaine () gmail com>
Date: Tue, 25 Nov 2008 18:37:01 -0700

Wireshark would be a bad tool to use for this purpose.  What OS's do you
have available to you? 

Probably the most prevalent monitoring tool out there is MRTG -
http://oss.oetiker.ch/mrtg/

Cheers,

---

Tremaine Lea
Network Security Consultant
Intrepid ACL
Paranoia for hire

Be careful of reading health books. you may die of a misprint. - Mark
Twain
On Tue, 2008-11-25 at 11:51 -0600, Terra Frost wrote:
I have four computers all plugged into a hub and I'd like to see which
one (well, which IP address) is sending / receiving the most data.  To
do this, I was thinking I could just install a package that would
tabulate such statistics using promiscuous mode.  Wireshark can sniff
packets via promiscuous mode but if it can be used in this manner, I'm
unsure of how.

I'm also not interested in real time statistics - I just want to know
how much data has been sent / received since the analysis program has
been running.

Any ideas?


Current thread: