LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 05-21-2009, 01:29 PM   #1
Darrell22
Member
 
Registered: Nov 2003
Posts: 83

Rep: Reputation: 15
Question Monitor Network activity by website?


Dear experts,


I use a firewall on my XP machines.

And, set task manager to come up on startup.
This way I can watch any network activity that is ocurring.


Usually, I can be pretty sure that the network activity is
coming from me. But sometimes there is activity not from me.
I will run netstat to see the IP and HTTP addresses.
Often it can be a background processes running, such as updates.

But what if is it is malicious?

What website is that coming from????

I'd like to get some software that will summarize network
activity by website and IP address. In real time.

So, if I see a lot of actvity on task manager networking,
I will see exactly which websites and IP addresses that
activity is associated with.

I noticed that Linux has iptraf. This is a good start.
From what I can see, it shows me all the activity.
But I don't see a way to summarize this activity by
website or IP address.

What are some software packages that will summarize the
network activity by website? Ideally, for free
(similar to process monitor, or explorer).


Thanks a lot!
 
Old 05-21-2009, 05:06 PM   #2
eco
Member
 
Registered: May 2006
Location: BE
Distribution: Debian/Gentoo
Posts: 412

Rep: Reputation: 48
I'd use iptraf as you mentioned for an overview of what is going through your firewall (linux) and if you need more detail, use tcpdump.
 
Old 05-22-2009, 12:34 AM   #3
suga_rray
LQ Newbie
 
Registered: Dec 2004
Location: India
Distribution: Debian Lenny
Posts: 6

Rep: Reputation: 1
Lightbulb

Darrell, a simple (both in configuration and in details) solution with web interface would be darkstat.

Its two minutes to configure and get going. Instead of giving the netmask in the config as 192.168.1.0/24, try 192.168.1.0/255.255.255.0. The former gave me trouble when I tried, not sure why.

And if you are looking for something without web interface, I like to use etherape a lot. This gives the real time traffic usage, with from-to ip/host and protocol/port etceteras.

Last edited by suga_rray; 05-22-2009 at 12:37 AM. Reason: To add a little more details.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
IPTables Activity Monitor? SlowCoder Linux - Security 2 04-20-2007 09:20 AM
How to monitor display activity of another computer in the network? hardian_97 Linux - Networking 3 05-18-2006 10:31 PM
Network activity monitor alpha754293 Linux - Newbie 2 05-16-2006 11:27 PM
monitor user activity alagenchev Linux - Security 5 01-20-2006 10:02 PM
What do you use to monitor server activity? Wonderer Slackware 8 11-02-2003 11:33 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 07:28 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration