Hello, I have a network capture that contains all the exchanges between a device and some remote servers, there are a lot of exchanges, on different destinations, on different protocols (ntp, http, https, etc.) and I would like to build a Flow Graph but at a macro level, that shows only the interactions between my device and the remote servers. For instance one arrow that represents exchanges for NTP trafic between my device and destination A, if possible with FQDN and not with IP address, one arrow for HTTPS traffic exchanges with destination B, and so on. Is anybody knows how to achieve this ? Thanks in advance. Regards. asked 18 Jan '16, 08:28 giraudeau |
2 Answers:
Does ntop help here? answered 18 Jan '16, 21:34 Jaap ♦ |
See my answer to a very similar question:
Plus:
Regards answered 19 Jan '16, 07:26 Kurt Knochner ♦ |