Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

tool that monitores what IP address are connecting to a certain service

Posted on 2011-03-09
10
Medium Priority
?
343 Views
Last Modified: 2013-12-04
anyone has a recommandation for a good tool that  can monitor which IP address connect to a certain service?
0
Comment
Question by:Amien90
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
  • +2
10 Comments
 
LVL 10

Expert Comment

by:abbright
ID: 35080342
Try running "netstat".
0
 
LVL 4

Expert Comment

by:parnasso
ID: 35080385
I recommend you tcpview from Sysinternals. Although its very basic, I think it is very handy.
0
 
LVL 1

Expert Comment

by:DColclazier
ID: 35080412
the netstat command can help:

"netstat -ano" will list all UDP/TCP active/listening ports.


A more thorough method would be to install a packet monitoring tool such as WireShark on the server containing the services you want to monitor.

Find out what port is associated with the particular service, start the monitor, and limit the filter to only show connections to that port.


http://www.jdcnetworksolutions.com
0
Automating Your MSP Business

The road to profitability.
Delivering superior services is key to ensuring customer satisfaction and the consequent long-term relationships that enable MSPs to lock in predictable, recurring revenue. What's the best way to deliver superior service? One word: automation.

 

Author Comment

by:Amien90
ID: 35080415
i know tcpview .. where can i see a list of all IP's that connected to a certain service?
0
 
LVL 10

Expert Comment

by:abbright
ID: 35080427
netstat gives you the list of ports where a connection exists and the remote host connecting to it.
0
 

Author Comment

by:Amien90
ID: 35080456
well . i dont need that information .. a certain user is connecting quite alot to a certain service. I want to know what the IP address is.
0
 
LVL 10

Expert Comment

by:abbright
ID: 35080513
If you know the port the service is listening "netstat -n" gives you the IP-address that connect to it.
0
 
LVL 4

Expert Comment

by:parnasso
ID: 35081258
With TCPView you can see the connections that service has opened. When you run TCPView, in the ProcessName column, you see processes names. The services are those whose name is svchost (the service host process). In order to know exactly which service is inside that host, right click over any svchost.exe and click on Properties and check the command line to find your service.
0
 
LVL 4

Accepted Solution

by:
parnasso earned 2000 total points
ID: 35081325
In addition to TCPView, you can also take a look at Processexplorer. This tool is a kind of a swiss knife.

When you start processexplorer, you will see a list of all running processes in your system. The services are below a process called service.exe. There you will see many svchost.exe and other things, but the most important is that if you right click on one, check Properties, and choose the TCP/IP sheet. There you will see something like the following picture:

 Process explorer TCP/IP view
Hope it helps
0
 
LVL 17

Expert Comment

by:chuku
ID: 35125334
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…
Suggested Courses

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question