Run a transparent Squid proxy on the host that sees all the traffic.
2009/5/14 JJB
<onephatcat@xxxxxxxxxxxxx>
JJB wrote:
> Can someone recommend an open-source product similar to ntop that would
> allow me to see, real time, url's visited per host & top visited urls?
>
> Ideally, I need something that will run on RedHat, and provide a web-gui
> interface.
>
What I really mean is I want to monitor our LAN to see where our users
are going - I'm really interested in figuring out how the bulk of our
bandwidth is being used - Wireshark tells me that someone, for instance,
is pulling lots of data from a CDN but not what the website they are
going to is. I don't want to run a continuous sniff as that would be a
massive file, so I'm looking for something accumulator based like ntop.