Hello, I have configured a packet sniffer sensor as below: Sensor type: packet sniffer custom

Exclude Filter: EtherType[ARP]

Channel Definition:

  1. 1:TCP Protocol[TCP]
  2. 2:UDP Protocol[UDP]
  3. 3:ICMP Protocol[ICMP]

Log Stream Data to Disk: Only for the "Other" channel

All the rest is default. The sensor works fine, I use the toplist "TOP TALKERS" to see which IPs use most bandwidth, then I go in the top chart and I see Other channel with high usage bandwidth, for this reason I seleceted the the option to log to disk "Only for the Other channel" to understand what's going on. But in the \StreamLog folder the csv file has only few rows and I don't understand who use that high bandwidth.


Article Comments

Hello,

Thank you for the KB-Post. Please bear in mind, the "Other"-entry in the KB is something else: What does the 'other'-entry in my TopConnections/TopTalkers mean?

best regards.


Sep, 2017 - Permalink