whroadmin
asked on
Remotely starting wireshark
How can I start a capture due to a monitored threshold being met?
ASKER
I have two 1g circuits into my network. i have nogios and active monitor watching them for ddos attacks. Now, should they detect that the circuit went from 300Mbs to 998Mbs, they send me an alert, but i also want them to start a batch file that will start a wireshark capture. I have the bat file, i just need some way for it to be started by nagios or active monitor.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
You can remotely monitor a system for example:
ssh remote tshark -w file -i ethX not port 22
(Prevent port 22 from being monitored, and write to the local file 'file'
while monitoring ethX. Port 22 would measure also the output of t-shark)..