Solved

Filtering output from TCPView

Posted on 2010-08-28
4
1,240 Views
Last Modified: 2012-05-10
Is there a way to filter by one of the display fields of TCPView?
For instance, if I were to filter by a given local port, say 25 and output the results to a text file over a period of time, would this be feasible?

Any help or suggestion from an expert(s) would be most appreciated. Thanks
0
Comment
Question by:garychu
  • 2
4 Comments
 
LVL 3

Assisted Solution

by:michko-au
michko-au earned 100 total points
ID: 33551655
0
 
LVL 68

Accepted Solution

by:
Qlemo earned 400 total points
ID: 33552565
Just using Currports isn't enough - you need to set up something in it, of course. You need to switch on Auto Refresh via the Options menu, and set it to the period of time you want to monitor changes. And then you need to configure and switch on logging in the File menu. I assume you have already added an application or port filter, and changed the display settings, eg. to exclude listening ports.

Do you want to just log something like.
Outlook opened SMTP to 1.1.1.1 at 01/09/2010 11:30:00
Outlook closed SMTP to 1.1.1.1 at 01/09/2010 11:30:02
? Or do you need the traffic contents?
0
 

Author Comment

by:garychu
ID: 33554545
Thanks, experts for the qucik and ready responses.
I have not heard of Currports before this.
I have found Wireshark a bit overwhelming for my lack of experience.
Will certainly give Currports a go.
Immediately, my attention is on a specific computer in a network which I suspect has been compromised by a spambot(s). Consequently, I need to monitor it for a period of time.
Thus adding a filter for 25 will suffice. Packet contents are of no interest.
May have to also add Outlook as an application because some spambots work through Outlook I understand.
Your further comments will be most helpful as I may be way off course.
Thanks
0
 
LVL 68

Expert Comment

by:Qlemo
ID: 33554976
That should do. But you have to let CurrPorts running on the "offending" machine, else you won't have process information available.
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

David Varnum recently wrote up his impressions of PRTG, based on a presentation by my colleague Christian at Tech Field Day at VMworld in Barcelona. Thanks David, for your detailed and honest evaluation!
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now