Solved

monitor bandwidth usage for specific workstation in domain

Posted on 2014-02-19
8
977 Views
Last Modified: 2014-02-20
Hello,

I would like to know what tools/ways I have to monitor a specific workstation in our domain environment for bandwidth usage, I can see in our FW that the bandwidth usage coming from this workstation is high and I would like to know which application running on his workstation is responsible for this.  I can see the list of applications remotely using tasklist from CMD but that does not provide me with the bandwidth towards the WAN.

This has to be done under the radar.
the OS: win7

Thanks.
0
Comment
Question by:iNc0g
8 Comments
 
LVL 6

Expert Comment

by:alexgreen312
ID: 39869717
There is a solar winds netflow traffic analyzer, it's a 30 day free trial and pretty decent
0
 
LVL 37

Accepted Solution

by:
Bing CISM / CISSP earned 500 total points
ID: 39869910
try TCPView, "a Windows program that will show you detailed listings of all TCP and UDP endpoints on your system, including the local and remote addresses and state of TCP connections."

it may give you the traffic data per process, as shown below.

TCPView v3.05
FYI - TCPView v3.05
http://technet.microsoft.com/en-au/sysinternals/bb897437.aspx
0
 

Author Comment

by:iNc0g
ID: 39870260
Regarding TCPView - I need a way to monitor an end-user workstation without his knowledge so I can really detect whether he's "abusing" the bandwidth, can this app run remotely? it doesn't seem so.
0
 
LVL 37

Expert Comment

by:Bing CISM / CISSP
ID: 39870424
YES, you can. you need to use the console version of TCPView (tcpvcon.exe) and PsExec together.

FYI - PsExec v2.0
http://technet.microsoft.com/en-au/sysinternals/bb897553.aspx
0
Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

 

Author Comment

by:iNc0g
ID: 39870500
I see, so you mean copying the tcpvcon.exe to the remote workstation and open it using psexec, correct ?
0
 
LVL 37

Expert Comment

by:Bing CISM / CISSP
ID: 39870617
yes.

don't forget to check PSEXEC's help for correct command line parameters to be used for calling TCPVCON.EXE.
0
 
LVL 3

Expert Comment

by:Mintar
ID: 39872299
To monitor without his acknowledge, you need to check another passive network monitoring programs.
A passive network monitoring program can parse and monitor network packets from a mirroring port of your switch.

Programs you can try:
1. WFilter Free  http://www.imfirewall.us/wfilterfree.htm

2. Wireshark http://www.wireshark.org
0
 
LVL 37

Expert Comment

by:Bing CISM / CISSP
ID: 39872755
> To monitor without his acknowledge, you need to check another passive network monitoring programs. A passive network monitoring program can parse and monitor network packets from a mirroring port of your switch.

that way can't provide per application / process traffic statistics, only per protocol or port traffic can be counted. it also needs additional hardware including network switch and computer (physical or virtual machine).
0

Featured Post

Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
This paper addresses the security of Sennheiser DECT Contact Center and Office (CC&O) headsets. It describes the DECT security chain comprised of “Pairing”, “Per Call Authentication” and “Encryption”, which are all part of the standard DECT protocol.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now