Solved

monitor bandwidth usage for specific workstation in domain

Posted on 2014-02-19
8
985 Views
Last Modified: 2014-02-20
Hello,

I would like to know what tools/ways I have to monitor a specific workstation in our domain environment for bandwidth usage, I can see in our FW that the bandwidth usage coming from this workstation is high and I would like to know which application running on his workstation is responsible for this.  I can see the list of applications remotely using tasklist from CMD but that does not provide me with the bandwidth towards the WAN.

This has to be done under the radar.
the OS: win7

Thanks.
0
Comment
Question by:iNc0g
8 Comments
 
LVL 7

Expert Comment

by:Alex Green
ID: 39869717
There is a solar winds netflow traffic analyzer, it's a 30 day free trial and pretty decent
0
 
LVL 37

Accepted Solution

by:
bbao earned 500 total points
ID: 39869910
try TCPView, "a Windows program that will show you detailed listings of all TCP and UDP endpoints on your system, including the local and remote addresses and state of TCP connections."

it may give you the traffic data per process, as shown below.

TCPView v3.05
FYI - TCPView v3.05
http://technet.microsoft.com/en-au/sysinternals/bb897437.aspx
0
 

Author Comment

by:iNc0g
ID: 39870260
Regarding TCPView - I need a way to monitor an end-user workstation without his knowledge so I can really detect whether he's "abusing" the bandwidth, can this app run remotely? it doesn't seem so.
0
Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

 
LVL 37

Expert Comment

by:bbao
ID: 39870424
YES, you can. you need to use the console version of TCPView (tcpvcon.exe) and PsExec together.

FYI - PsExec v2.0
http://technet.microsoft.com/en-au/sysinternals/bb897553.aspx
0
 

Author Comment

by:iNc0g
ID: 39870500
I see, so you mean copying the tcpvcon.exe to the remote workstation and open it using psexec, correct ?
0
 
LVL 37

Expert Comment

by:bbao
ID: 39870617
yes.

don't forget to check PSEXEC's help for correct command line parameters to be used for calling TCPVCON.EXE.
0
 
LVL 3

Expert Comment

by:Mintar
ID: 39872299
To monitor without his acknowledge, you need to check another passive network monitoring programs.
A passive network monitoring program can parse and monitor network packets from a mirroring port of your switch.

Programs you can try:
1. WFilter Free  http://www.imfirewall.us/wfilterfree.htm

2. Wireshark http://www.wireshark.org
0
 
LVL 37

Expert Comment

by:bbao
ID: 39872755
> To monitor without his acknowledge, you need to check another passive network monitoring programs. A passive network monitoring program can parse and monitor network packets from a mirroring port of your switch.

that way can't provide per application / process traffic statistics, only per protocol or port traffic can be counted. it also needs additional hardware including network switch and computer (physical or virtual machine).
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Layer 2 versus layer 3 10 86
Sonicwall TZ 205- Dropping Incoming E-mail as IP Spoof 13 165
nipper studio 2 44
By pass website on ASA for Websense 4 70
It’s 2016. Password authentication should be dead — or at least close to dying. But, unfortunately, it has not traversed Quagga stage yet. Using password authentication is like laundering hotel guest linens with a washboard — it’s Passé.
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question