Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-users: Re: [Ethereal-users] Collecting data for detailed traffic analyses

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Hansang Bae <hbae@xxxxxxxxxx>
Date: Thu, 20 Apr 2006 22:31:41 -0400
On 01:54 PM 4/20/2006, Mike Armstrong wrote:
>I need a way to collect basic traffic packet data (source IP & port, destination IP & port, byte count) at T1 speeds.  Ultimately I want to produce an in/out matrix showing where traffic originated and where it went. Any suggestions how this might be accomplished?  Basically, I'd like to record just packet header information for later analysis. 


If using Cisco or Juniper gear, you can use netflow for the former and cflow for the latter.

There are many opensource c/netflow collectors.

You could you Ethereal as well, but I think it would be somewhat clumsy.  There are other tools that can do the job better.   For example, http://analyzer.polito.it/ looks like it may have better "statistics" support then Ethereal.

hsb