Ad Widget

Collapse

monitoring specific port traffic

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • asd01248967
    Junior Member
    • Dec 2015
    • 7

    #1

    monitoring specific port traffic

    Hello! everyone
    First apologized for poor english that express not clear-cut

    Q1.Have anyone know monitoring specific port traffic by item key(in、out、sum)
    I research Zabbix documentation>Configuration>Items>Item types>Zabbix agent & Windows-specific item keys
    but,I don't seem any could accomplish target for item key

    Q2.Or have other project can accomplish this requirement
    e.q:make a scripts by self and to co-operate User parameters
    hinet:I don't have any program experience

    thanks you very mych!!ALL!!
    Last edited by asd01248967; 26-07-2016, 05:01.
  • asd01248967
    Junior Member
    • Dec 2015
    • 7

    #2
    Please...Help

    Hello...
    Can someone tell me any answer or hint?

    or gave a URL ,than i could study myself

    Comment

    • LenR
      Senior Member
      • Sep 2009
      • 1005

      #3
      What do you mean by port? Like traffic for port 80 or 443?

      Comment

      • asd01248967
        Junior Member
        • Dec 2015
        • 7

        #4
        thanks you reply

        Originally posted by LenR
        What do you mean by port? Like traffic for port 80 or 443?
        yes!
        that's is my target
        have any idea can share with me?
        apologized for poor english
        thank you!

        Comment

        • LenR
          Senior Member
          • Sep 2009
          • 1005

          #5
          Ok, how would you get this statistic from the command line? I briefly researched this, but I don't know if this is a good answer, this poster did it with iptables:
          http://unix.stackexchange.com/questi...r-network-port

          Once you can get the traffic counted, then you need a way to extract it. I think some form of iptables -L -vn | grep | cut could get you a single line with the desired port's byte or packet count.

          Now you feed that to Zabbix via a user parameter or zabbix_sender, if your value is total, set the zabbix item to store delta/sec

          This is a standard thought process of extending monitoring to items not built into zabbix and/or the OS.

          Comment

          • LenR
            Senior Member
            • Sep 2009
            • 1005

            #6
            Be aware that placement and other iptables rules can effect rules that are just for accounting. It's been awhile since I went this deep into iptables, but I think you would want those accounting rules after any rules that would drop traffic to these ports but before any rule allowing "established,related" traffic.

            For example, count of dropped packets & bytes from a blocked address range to port 10051

            iptables -L -vnx | grep 10051 | grep DROP | grep 10.133.9
            142385 8543100 DROP tcp -- * * 10.133.9.0/24 0.0.0.0/0 tcp dpt:10051

            Comment

            • asd01248967
              Junior Member
              • Dec 2015
              • 7

              #7
              Originally posted by LenR
              Ok, how would you get this statistic from the command line? I briefly researched this, but I don't know if this is a good answer, this poster did it with iptables:
              http://unix.stackexchange.com/questi...r-network-port

              Once you can get the traffic counted, then you need a way to extract it. I think some form of iptables -L -vn | grep | cut could get you a single line with the desired port's byte or packet count.

              Now you feed that to Zabbix via a user parameter or zabbix_sender, if your value is total, set the zabbix item to store delta/sec

              This is a standard thought process of extending monitoring to items not built into zabbix and/or the OS.
              I understand what you mean and method
              but...needed feasibility method is for Windows Server 2008 R2 or Windows Server 2012 R2
              I research on Internet and then wasn't find can to do monitoring Windows specific port traffic(in & out)

              Please forgive me for express not clear-cut
              thanks
              Last edited by asd01248967; 27-07-2016, 08:07.

              Comment

              • troffasky
                Senior Member
                • Jul 2008
                • 567

                #8
                If such statistics are collected by the OS [and I'm not optimistic that they are] they may be available with WMI?

                If the OS doesn't collect them, the application may do.

                You may be able to try the iptables-style approach on Windows - create allow rules for the traffic you're interested in [if you don't have them already] and see if you can get stats from Windows firewall.

                Finally, tshark has statistics options - you could run tshark in a loop, dumping statistics once a minute [and discarding the capture].

                Comment

                • asd01248967
                  Junior Member
                  • Dec 2015
                  • 7

                  #9
                  Originally posted by troffasky
                  If such statistics are collected by the OS [and I'm not optimistic that they are] they may be available with WMI?

                  If the OS doesn't collect them, the application may do.

                  You may be able to try the iptables-style approach on Windows - create allow rules for the traffic you're interested in [if you don't have them already] and see if you can get stats from Windows firewall.

                  Finally, tshark has statistics options - you could run tshark in a loop, dumping statistics once a minute [and discarding the capture].
                  WOW~!!
                  Thanks you very much your advice
                  I will learn how to using tshark function

                  Comment

                  Working...