This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi all, how can I log IPs wich are using bandwidth above threshold?

For example I want to log computer IPs which are using more than 1Mbps of bandwith at any given point of time. How can I do this using tshark?

asked 21 May '14, 23:20

CJ22's gravatar image

CJ22
11114
accept rate: 0%

edited 22 May '14, 01:51

grahamb's gravatar image

grahamb ♦
19.8k330206


Only capinfos can show you the average data byte/bit rate similar to the Wireshark -Statistics - Summary. It will not be in real time and the calculations are for the entire packet capture.

For network statistics look at tools like ntop or darkstat.

permanent link

answered 23 May '14, 13:26

Roland's gravatar image

Roland
7642415
accept rate: 13%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×832
×57
×6

question asked: 21 May '14, 23:20

question was seen: 1,776 times

last updated: 23 May '14, 13:26

p​o​w​e​r​e​d by O​S​Q​A