From owner-freebsd-questions@FreeBSD.ORG Wed Jan 27 15:32:48 2010 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 85127106566C for ; Wed, 27 Jan 2010 15:32:48 +0000 (UTC) (envelope-from dan@dan.emsphone.com) Received: from email1.allantgroup.com (email1.emsphone.com [199.67.51.115]) by mx1.freebsd.org (Postfix) with ESMTP id 4BF318FC0A for ; Wed, 27 Jan 2010 15:32:47 +0000 (UTC) Received: from dan.emsphone.com (dan.emsphone.com [199.67.51.101]) by email1.allantgroup.com (8.14.0/8.14.0) with ESMTP id o0RFWipd017835 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for ; Wed, 27 Jan 2010 09:32:45 -0600 (CST) (envelope-from dan@dan.emsphone.com) Received: from dan.emsphone.com (smmsp@localhost [127.0.0.1]) by dan.emsphone.com (8.14.4/8.14.3) with ESMTP id o0RFWirJ050645 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for ; Wed, 27 Jan 2010 09:32:44 -0600 (CST) (envelope-from dan@dan.emsphone.com) Received: (from dan@localhost) by dan.emsphone.com (8.14.4/8.14.3/Submit) id o0RFWh0F050625; Wed, 27 Jan 2010 09:32:43 -0600 (CST) (envelope-from dan) Date: Wed, 27 Jan 2010 09:32:43 -0600 From: Dan Nelson To: Glenn McCalley Message-ID: <20100127153243.GV50360@dan.emsphone.com> References: <10713CBA99A4455684AA7CB50185C3A3@GLENN2> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <10713CBA99A4455684AA7CB50185C3A3@GLENN2> X-OS: FreeBSD 7.2-STABLE User-Agent: Mutt/1.5.20 (2009-06-14) X-Virus-Scanned: clamav-milter 0.95.3 at email1.allantgroup.com X-Virus-Status: Clean X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-2.0.2 (email1.allantgroup.com [199.67.51.78]); Wed, 27 Jan 2010 09:32:45 -0600 (CST) X-Scanned-By: MIMEDefang 2.45 Cc: freebsd-questions@freebsd.org Subject: Re: MRTG vs. character of traffic X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 27 Jan 2010 15:32:48 -0000 In the last episode (Jan 27), Glenn McCalley said: > OK so the data center says my traffic is unreasonable. Turns out they may > be correct. MRTG is showing one server with a totally unreasonable level > of outbound traffic so now I know which machine to study. Are there > recommendations for a tool to tell me what KIND of traffic, not just the > gross bit rate? I want to find that idiot that's causing all the > bandwidth. tcpdump or wireshark would be a good start, if you're around when it happens. -- Dan Nelson dnelson@allantgroup.com