Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-users: [Ethereal-users] Traffic burst detector.

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: "Rob Miller" <rmiller@xxxxxxxxxxxxxx>
Date: Wed, 15 Dec 2004 13:04:14 -0700
Title: Traffic burst detector.

Thanks to both Uwe Geuder and Jack Coates for their reply.

 -----Original Message-----
From:   Rob Miller 
Sent:   Friday, December 10, 2004 08:30
To:     'ethereal-users@xxxxxxxxxxxx'
Subject:        Traffic burst detector.

Hello,

We are trying to detect where burst of traffic is coming from. We've used Ethereal to view all traffic over a period of time and find that there are 15 second bursts of traffic occurring sporadically from one or more of our network stations. Unfortunately There is no way to tell where the traffic is coming from as it is buried among thousands of other packets.

What we need is a monitor that measures traffic per second and if the traffic is greater than a certain threshold, it captures that second's worth of packets and puts it into file to be analyzed later. The analysis would have some way of showing all the different sources of traffic along with the total amount for each source.

Could you suggest some simplified way of analyzing our traffic from that point of view.

                                                                                 
Robert G. Miller
Systems Integration Manager
ResourceLink Software Inc
(403) 245-0220
rmiller@xxxxxxxxxxxxxx