Link to home
Start Free TrialLog in
Avatar of whroadmin
whroadmin

asked on

Remotely starting wireshark

How can I start a capture due to a monitored threshold being met?
Avatar of noci
noci

With wireshark comes tshark, the text variant.
You can remotely monitor a system for example:

ssh remote tshark -w file -i ethX not port 22

(Prevent port 22 from being monitored, and write to the local file 'file'
while monitoring ethX.   Port 22 would measure also the output of t-shark)..
Avatar of whroadmin

ASKER

I have two 1g circuits into my network. i have nogios and active monitor watching them for ddos attacks. Now, should they detect that the circuit went from 300Mbs to 998Mbs, they send me an alert, but i also want them to start a batch file that will start a wireshark capture. I have the bat file, i just need some way for it to be started by nagios or active monitor.
ASKER CERTIFIED SOLUTION
Avatar of noci
noci

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial