Solved

Wireshark log file size problem

Posted on 2009-04-02
4
1,294 Views
Last Modified: 2012-05-06
I have 5 servers on the network I am managing, now the trouble I am having is, due to very high traffic, the log files that are generated have a very high size (Like 5 GB per hour) this is because its monitoring all protocols.

It monitors so many that I dont need, I just need a few like HTTP, SMTP and common ones. How can I EFFECTIVELY set these rules?

The file size should be reduced to a few MBs per hour.

Please advise.


Regards
0
Comment
Question by:westdata
  • 2
4 Comments
 
LVL 33

Expert Comment

by:MikeKane
ID: 24052359
Sounds like you should set some Capture filters to only capture the IP's for the servers and port ranges you are interested in:  

http://wiki.wireshark.org/CaptureFilters
http://www.wireshark.org/docs/wsug_html_chunked/ChCapCaptureFilterSection.html

For Example, a capture filter for smtp that captures traffic to and from a particular host
"tcp port 25 and host 10.10.10.1"

or a filter for SMTP and WEB
host 10.10.10.1 and  (port 80 or port 25)

      

0
 

Author Comment

by:westdata
ID: 24054193
Thankyou so much MikeKane :)

One more question, I saw many useful filters there, now how can I use more than two filters at a time.

When I go to "How the Capture option.." on the quick link bar, I see just I can enter just one filter. How can I add more filters like:

port not 53 and not arp
and
dst net 192.168.0.0/24
and...


Any idea?

Thanks again!
0
 
LVL 16

Accepted Solution

by:
SteveJ earned 500 total points
ID: 24055289
(port not 53 and not arp) and (dst net 192.168.0.0/24)

Good luck,
Steve
0
 

Author Closing Comment

by:westdata
ID: 31565899
Great!
0

Featured Post

NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
HP network exams 3 56
VLAN Issue 4 68
Boot Camp 3 56
Microwave IP VPN or Wireless Bridging 26 46
#Citrix #Citrix Netscaler #HTTP Compression #Load Balance
For many of us, the  holiday season kindles the natural urge to give back to our friends, family members and communities. While it's easy for friends to notice the impact of such deeds, understanding the contributions of businesses and enterprises i…
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question