Hello, I have configured a packet sniffer sensor as below: Sensor type: packet sniffer custom
Exclude Filter: EtherType[ARP]
Channel Definition:
- 1:TCP Protocol[TCP]
- 2:UDP Protocol[UDP]
- 3:ICMP Protocol[ICMP]
Log Stream Data to Disk: Only for the "Other" channel
All the rest is default. The sensor works fine, I use the toplist "TOP TALKERS" to see which IPs use most bandwidth, then I go in the top chart and I see Other channel with high usage bandwidth, for this reason I seleceted the the option to log to disk "Only for the Other channel" to understand what's going on. But in the \StreamLog folder the csv file has only few rows and I don't understand who use that high bandwidth.
Add comment