This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Can I use Wireshark to idenitify a bandwidth hog, i.e. a user/pc that is perhaps watching videos or on peer to peer file sharing networks and thus using high bandwidth?

Thank you

asked 06 Mar '12, 12:07

IT%20Tropolis's gravatar image

IT Tropolis
6224
accept rate: 0%


Yes you can...

... by using "Statistics -> Endpoints". Click on the IP tab and then sort on the column you find most interesting.

permanent link

answered 06 Mar '12, 12:12

SYN-bit's gravatar image

SYN-bit ♦♦
17.1k957245
accept rate: 20%

hello SYN-bit, after go to Statistics-Endpoints, the only IP tab I have is IPv4:332. Is that the one I should click on. To find the bandwidth hog, which column should I look into Bytes,Tx Packets, TX Bytes, RX Packets,Rx Bytes?

(28 Mar '16, 09:24) ipodtrip

I would sort the rows first by Bytes A->B and then by Bytes B->A (by clicking on column name) and look for the maximum value of both (as assignment of A and B roles to endpoints of a given conversation depends on the order of occurrence of the addresses in the capture). But having no TCP and/or UDP tab is strange, haven't you disabled the dissectors?

(28 Mar '16, 13:31) sindy

let me try to disable the dissectors. Really appericate your help.

(01 Apr '16, 10:04) ipodtrip

It may well be a chain of misunderstandings. I thought you complained that there are no other tabs than the IP one in the Statistics -> Endpoints window, so I've suggested you to check whether the dissectors of TCP and UDP are not disabled by chance, assuming that disabling them would cause the TCP and UDP tabs to go missing. But maybe you actually wanted IPv6 on top/instead of IPv4?

I've checked now and found that disabling TCP and UDP dissectors doesn't hide their tabs, it only makes them empty. So do not disable the dissectors (or re-enable them if you already did).

Which version of Wireshark do you run? In 2.0.2, pressing the Endpoint Types button gives you a checklist of tabs to be shown, so you can verify that tickboxes next to layers/protocols you are interested in are checked.

(01 Apr '16, 13:50) sindy
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×57
×16
×8

question asked: 06 Mar '12, 12:07

question was seen: 41,700 times

last updated: 01 Apr '16, 13:51

p​o​w​e​r​e​d by O​S​Q​A