Solved

network analyzer

Posted on 2013-12-12
5
317 Views
Last Modified: 2014-01-18
Hi guys,

Is there a software I can use to analyzer a network to see what is taking place per computer.

I have a suspection that someone is downloading stuff from utorrent and I would like to know.

if you guys have any tool I can use please let me know.

thanks  in advance
0
Comment
Question by:MVGtechnology
5 Comments
 
LVL 7

Accepted Solution

by:
BobintheNoc earned 500 total points
ID: 39714287
Your firewall is probably the easiest place to examine for any and all traffic or internet questions. If your firewall is off commercial for business quality, you should be able to show your translation connections or open connections.  if you find a computer IP address on your internal network is establish connectionsor has many UDP streams to a variety of remote address is, you have likely found your culprit.another method involves using a packet capture software such as Wireshark. With Wireshark, you can identify conversations and decode the packet streams with a good chance Wireshark can specifically identify torrent based connections. The trick with using a capture software is to find a good  position to plug into or connect your capture interface in a spot that is exposed to all traffic. A good spot is usually again at the firewall, either right in front of it or behind.

many firewalls allow you to actually perform packet capture at the firewall for downloading and then analysis bye software like Wireshark. There are many other ways 2 make your determination, depending on your existing configuration and you're network knowledge sophistication. With further detail on what you have done and you're available resources, we can help you narrow and identify your traffic.
0
 
LVL 14

Expert Comment

by:BlueCompute
ID: 39714296
What is your gateway device?  Usually it's fairly easy to spot torrent users as they will be opening a lot of sessions to unfamiliar IPs.
0
 
LVL 6

Expert Comment

by:vmagan
ID: 39714347
Wireshark works great and its free.
0
 
LVL 14

Expert Comment

by:Giovanni Heward
ID: 39714428
Wireshark is great, however you need to enable a port mirroring on your switch stack (also referred to as a SPAN port for Cisco devices.)

Microsoft Message Analyzer is also a good tool, it allows you to resemble HTTP sessions (for example), so you can actually view the web pages and images your users have downloaded.  Again, port mirroring would be required.

As mentioned above, the easiest method may be to enable logging at your firewall.  You can install a syslog server to capture activity over time for future analysis.
0
 
LVL 3

Expert Comment

by:jb_yow
ID: 39716070
You can also try network monitoring software based on netflow like PRTG - http://www.paessler.com/prtg and Manage Engine's Netflow Analyzer - http://www.manageengine.com/products/netflow/.
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
configuring snmp v2 or v3 on Cisco switches 2 48
network + 7 80
Nexus OS - OSPF Command 3 49
Botnet detection help me please 21 79
Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
Is your computer hacked? learn how to detect and delete malware in your PC
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

914 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now