?
Solved

Deciphering netstat output

Posted on 2013-06-12
2
Medium Priority
?
598 Views
Last Modified: 2013-06-17
When running the netstat command with the 'a' and 'n' options, the output includes numerous lines resembling the following:

udp        0      0  *.*                    *.*

What does this mean. I'm concerned about the sheer number of them (there are 945 such records). Is this a problem?
0
Comment
Question by:babyb00mer
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 19

Expert Comment

by:jools
ID: 39242997
looks like there may be a column missing from the output, I would have thought you should see the port numbers udp is listening on and they are probably related to services.

If it's linux try running netstat -taupen which will give a full list and the daemon associated with the port.
0
 
LVL 68

Accepted Solution

by:
woolmilkporc earned 2000 total points
ID: 39243958
Hi,

these are probably UDP structures set aside by the kernel for communicating with application-layer servers, like nfsd, biod or automountd.

Is this an NFS server, and does it serve quite a bunch of active NFS mounts?

Find out how many NFS threads are running:

ps -Am -o pid,thcount,comm,args | grep -E "nfsd| biod"

(Please note the space in front of " biod"!)

Do the figures shown in the second column (roughly) correspond to the number of those UDP entries without a specific local address/port?
0

Featured Post

Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Using libpcap/Jpcap to capture and send packets on Solaris version (10/11) Library used: 1.      Libpcap (http://www.tcpdump.org) Version 1.2 2.      Jpcap(http://netresearch.ics.uci.edu/kfujii/Jpcap/doc/index.html) Version 0.6 Prerequisite: 1.      GCC …
Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
Connecting to an Amazon Linux EC2 Instance from Windows Using PuTTY.
In a previous video, we went over how to export a DynamoDB table into Amazon S3.  In this video, we show how to load the export from S3 into a DynamoDB table.
Suggested Courses
Course of the Month11 days, 1 hour left to enroll

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question