Snort mailing list archives

Re: How to simply sum up all the transferred bytes ?


From: "Ing. Daniel Manrique" <roadmr () entropia com mx>
Date: Mon, 9 Sep 2002 10:52:23 -0500 (CDT)



Someone asked a slightly similar question before, and everyone pointed him 
to ntop and other tools, stating, plainly, that snort is not the best tool 
for the traffic monitoring job.

http://www.ntop.org

ntop is sometimes considered overkill (everything but the kitchen sink on 
the sucker), so if your needs are indeed more simple, you could also take 
a look at darkstat or iptraf ; darkstat tries to be a "simpler ntop" and 
iptraf is a complete traffic analyzer for the console.

http://cebu.mozcom.com/riker/iptraf/
http://members.optushome.com.au/emikulic/net/darkstat/


As a snort newbie a question about using snort as a simple traffic monitor:

How can I measure the sum of bytes traffic between my personal local
computer and the net outside within a given period of time ?

The statistic should distinguish between
inbound and outbound traffic
and possibly the used ports
- 21, 22 (= all ftp)
- 80, 81, 8080 (=all html)
- * (=rest)

The time period is e.g. today.



-------------------------------------------------------
This sf.net email is sponsored by: OSDN - Tired of that same old
cell phone?  Get a new here for FREE!
https://www.inphonic.com/r.asp?r=sourceforge1&refcode1=vs3390
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: