Link to home
Start Free TrialLog in
Avatar of Dragon0x40
Dragon0x40

asked on

Create a baseline with Wireshark

Has anyone ideas on how to baseline a network with wireshark?

Span the port a workstation is on and then start capturing? Get the boot up, dhcp, start applications?

How about the network itself? With switches you only get broadcast and traffic to your computer.

How long should the capture last?

Do you need a capture for each model of workstation, laptop and server?

ASKER CERTIFIED SOLUTION
Avatar of eeRoot
eeRoot

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Dragon0x40
Dragon0x40

ASKER

Okay, so how do I use this baseline?

Do I need to take one every day, week, etc.?

How long should I capture the traffic for?

I don't have huge amounts of disk space to play with and spanning on a core router would need authorization because of the possibility of an increased load or affecting traffic flow.

Capture everything?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial