Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] top talkers by port usage or SYN attempts

From: "Giles Coochey" <gcoochey@xxxxxxxxxxx>
Date: Fri, 25 Jan 2008 10:42:17 +0100

To be honest, If they’re creating that many connections then it should be pretty obvious from eyes on the capture itself.

 


From: wireshark-users-bounces@xxxxxxxxxxxxx [mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of jacob c
Sent: 25 January 2008 00:27
To: wireshark-users@xxxxxxxxxxxxx
Subject: [Wireshark-users] top talkers by port usage or SYN attempts

 

I have a linux load balancer appliance where some user is constantly making too many connections to some unknow ip address. When this happens it eventually uses up all 65,000 ports. Is there some way to take a massive capture and then filter it out in wireshark by top port talkers and/or top syn attemptsby ip address? Any info would be very much appreciated.

 

Thank you,

 


Be a better friend, newshound, and know-it-all with Yahoo! Mobile. Try it now.