• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How to Alert on Single IP uploading too much?

Scheduled Pinned Locked Moved Traffic Monitoring
2 Posts 1 Posters 739 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    SkinnerVic
    last edited by Jan 18, 2018, 5:21 AM

    OK, so I have been reading about different ways to accomplish this simple task to no avail.  Here's what I am trying to do:

    I have a single client (maybe more down the line) that I know something is really wacky if they push too much data from LAN to WAN.  I just want to set some thresholds on up data over some unit time (like 1 min resolution) that if it exceeds XX kb/s, then send me an email (preferably a SMS).  I don't want to cap the client either, just know what's going on (discreetly).  8)

    I'm not interested in retaining any of the data for logging, etc.  I may want to see what the traffic is like for a week to set a reasonable level, then let it ride until further notice.

    I know I'm compiling two different skills - Monitoring, Notification.  You'd think I was pulling teeth.  I thought about using Snort and having it be a rule.  At this point, I'm all ears…

    Suggestions?

    1 Reply Last reply Reply Quote 0
    • S
      SkinnerVic
      last edited by Jan 19, 2018, 3:09 AM

      I decided to head the ntopng route.  OK, not quite what I was looking for but it's fancy and fast for my purposes as I found a solution and wanted to pass it along:

      In ntopng, there is per host alerting.  While it's not an email or sms, it does SLACK!!  Woot.  I just integrated a new workspace with my existing workspace in Slack and followed the instructions here:

      https://github.com/ntop/ntopng/blob/dev/doc/README.slack

      I set two threshold items - the Activity Time and Traffic, Layer 2 with the levels low to see what a baseline looked like.  Sure enough, it is quite gated unless it gets stupid.

      Hope this can help anyone else looking for this solution.  The only way it could be better is to split send/rec in Traffic, but it works for now!

      1 Reply Last reply Reply Quote 0
      2 out of 2
      • First post
        2/2
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
        This community forum collects and processes your personal information.
        consent.not_received