Solved

Network Activities Monitoring

Posted on 2008-10-07
9
211 Views
Last Modified: 2014-06-20
Dear All,

     I have a network with 500 users and I want to be able to monitor their activities like ( what there are downloading, the bandwidth, activities) what network software I could use for that.

Thanks
0
Comment
Question by:ibmas4002
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
9 Comments
 
LVL 7

Expert Comment

by:willbaclimon
ID: 22662291
What vendor switches do you have? If its cisco you can use netflow collector software.
0
 
LVL 32

Expert Comment

by:Kamran Arshad
ID: 22662610
Hi,

You need to setup a proxy server between your network. The proxy server (Cache+firewall) will log all the ftp and http based downloads. You can even restrict sites, limit the bandwidth, and monitor the bandwidth. There are two industry standard software-based proxy servers;

1- MS ISA Server
www.microsoft.com/ISAserver/default.mspx

2- Squid Cache Server
www.squid-cache.org

I personally recommend squid because it has all the basic features built-in and is open-source (free).

You may also have a look at hardware proxy appliance like bluecoat;

www.bluecoat.com
0
 
LVL 25

Accepted Solution

by:
Cyclops3590 earned 84 total points
ID: 22665785
uetian1707's suggestion of Squid is great for detailed monitoring of several protocols but doesn't quite capture everything you may want.

so long as you have a managed switch capable of port mirroring, something like Ntop is a perfect tool to collect detailed network statistics so you know who is taking up your link, what resources their using, how long, etc.  While Ntop does do Netflow, from what I've heard mirroring traffic to the ntop server is more reliable than using netflow.
0
Online Training Solution

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action. Forget about retraining and skyrocket knowledge retention rates.

 
LVL 7

Assisted Solution

by:willbaclimon
willbaclimon earned 83 total points
ID: 22681680
Port mirroring is good..I've never ran into a issue with netflow. The benefit of netflow is that you can run it on any device that supports it. No needs set up aggregation points.


0
 
LVL 7

Expert Comment

by:willbaclimon
ID: 22723700
If satisfied please close the question
0
 
LVL 20

Expert Comment

by:jimmymcp02
ID: 22780073
Hello ibmas4002,

http://www.wireshark.org/about.html

Regards,

jimmymcp02
0
 
LVL 3

Assisted Solution

by:pistanu
pistanu earned 83 total points
ID: 37729867
linux bridge and then or proxy server, or filtering with iptables and log the traffic that you're interest.

here is how you make the bridge:

http://www.usermadetutorials.com/2010/06/creating-a-linux-bridge-for-shaping-qos/

the user wont realize that they are under big brother eye.
0

Featured Post

Secure Your WordPress Site: 5 Essential Approaches

WordPress is the web's most popular CMS, but its dominance also makes it a target for attackers. Our eBook will show you how to:

Prevent costly exploits of core and plugin vulnerabilities
Repel automated attacks
Lock down your dashboard, secure your code, and protect your users

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Even if you have implemented a Mobile Device Management solution company wide, it is a good idea to make sure you are taking into account all of the major risks to your electronic protected health information (ePHI).
Meet the world's only “Transparent Cloud™” from Superb Internet Corporation. Now, you can experience firsthand a cloud platform that consistently outperforms Amazon Web Services (AWS), IBM’s Softlayer, and Microsoft’s Azure when it comes to CPU and …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question