Hello, Our Public IP address recently got blacklisted an i'm trying to find out what computer did it.

Is it possible to generate a report of some sort that shows me what computer requested a TCP connection to a certain IP address on the internet?

I have PRTG setup to monitor our internet Cisco router, and is logging both Netflow and SNMP.

Does anyone know if this is possible?

Regards, Peter


Article Comments

Dear Cojaxx8

This is not directly possible with PRTG.

In principle, you can create a Netflow sensor and create channels by filter rules to search for a match. However you need to know the match in beforehand, you also rely on a new occurrence of the IP to IP connection which you are looking for.

PRTG cannot generate the list you like to have, it can only show you the result of pre-defined filter rules.


Jun, 2015 - Permalink

No worries. Thanks for information. I didn't think it would have been possible but thought there was no harm in asking.

Cheers Peter


Jun, 2015 - Permalink