Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] finding the smoking gun for traffic spikes

From: Rogelio <scubacuda@xxxxxxxxx>
Date: Mon, 18 Jul 2011 09:46:02 -0300
Anyone know how I easily find unknown unicast flooding?

The only way I can think of how to do it would be to search the IO
graphs for bursts, then look at the MACs / IPs during those bursts,
and then try to compare those to a list of known good IP / MAC
addresses on the L2TP tunnel segment at that time.

I was hoping that there would be an easier way to filter out for it
rather than going through all of these steps.