I would like to know the following: 1) Bandwidth usage of our WAN at a certain period, certain point. 2) If the bandwidth usage is high, we want to know which IP, user, application, software used up the bandwidth at that certain period, certain point.

We use the PRTG to monitor the firewall SNMP and we can see the point 1 result. How can we get Point 2 result?

Is that Netflow can help us in this issue? If so, besides connect PRTG to the firewall for Netflow data, is there any other sensor we need build up to get the Point 2 data? We need estimate the cost required.

Thx alot. Ivan


Article Comments

Hi Ivan,

the bandwidth of the WAN interface can be measured with a simple SNMP traffic counter. In the historical data function it is possible to define any time period for analysis.

The IP and Port which consumes the bandwidth will be visible in a Netflow Sensor in the connection top list.

To use netflow you need to enable the netflow export on the firewall/router or switch. It is also possible to get this information from a mirroring port with a Packet Sniffer Sensor


Oct, 2013 - Permalink

So, for example, if I found the period 9:00-10:00 had abnormal high usage in through the SNMP traffic counter, can I drill down in the same page to see which computer is using up the bandwidth?

Can I get which user is using that problem computer?


Oct, 2013 - Permalink

If you have a flow or packet sniffing sensor for your Internet connection you could track down

the TopTalkers, TopProtocols and TopConnections for that hour.

please see

https://www.paessler.com/knowledgebase/en/topic/2923-how-do-i-discern-excessive-bandwidth-usage-with-prtg


Oct, 2013 - Permalink

Thx!

In PRTG, if we use flows or packet sniffing, is that support drill down function to see what is using up the bandwidth?

Is there any demo site which I can see the result of using flows or packet sniffing?

Ivan


Oct, 2013 - Permalink

the PRTG trial that you can download for testing supports all features that PRTG has to offer.

Flows and packet sniffing, too.

https://www.paessler.com/prtg/download


Oct, 2013 - Permalink

Dear Aurelio,

Is there any screen shot or demo site which we can access?

We have no time to trial each software to see whether it suit our requirement or not.


Oct, 2013 - Permalink

Ivan,

Generally you are able to do this with our Netflow Sensors but the caveat here is that you need to define which types of traffic you want to see when creating the sensor. When PRTG processes the data from Netflow, once it's done it does not retain the data for later analysis.

You can see the standard channels in the screenshots that are below. You can also define your own channels based on the information in this article.

Netflow

Larger Size


Oct, 2013 - Permalink