Snort mailing list archives

Re: Off topic a little - usage by port?


From: Alberto Gonzalez <ag-snort () cerebro violating us>
Date: Tue, 22 Oct 2002 10:45:26 -0700

hrm, iirc iptraf(http://www.iptraf.org) has statistics after you start sniffing. It runs on linux (console). Though sending SIGUSR1 to snort
will give you packet statistics, but not the way you want it.

   Hope it helps
       - Albert

Rich Adamson wrote:

I know this is a little off topic, but the folks that hang out here
may know...

I'm looking for a software app that can be used to monitor all traffic
mirrored from a switch port (as an example), that would accumulate
usage statistics by IP and tcp/udp port number. It would be great if
the app could be configured to gather stats for "either" source port
or destination port. Logging the usage stats to a file on some
predetermined interval would be helpfull.

Example:
 Source IP       Proto Dest Port Packets
 --------------- ----- --------- ---------
 123.123.123.123 udp   53        452
                 tcp   445       10
                 tcp   110       4,000
                 tcp   80        1,234
                 icmp  ---       22

Does anyone know of such an app or have any thoughts about something
that might be close that I can modify to do this? Doesn't need to be pretty, and I don't care if it runs under Linux or Win2k; either would be fine.

Rich
radamson () routers com

--
The secret to success is to start from scratch and keep on scratching.




-------------------------------------------------------
This sf.net emial is sponsored by: Influence the future of Java(TM) technology. Join the Java Community Process(SM) (JCP(SM)) program now. http://ad.doubleclick.net/clk;4699841;7576301;v?http://www.sun.com/javavote
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: