Wireshark - Graphic analysis tool. anyone knows?
17,654
Solution 1
Have you tried Wireshark's own "statistics" tools. You have some pretty nice tools to do endpoint conversation analysis (somehow similar to netflow), IO graphs, per protocol statistics, protocols hierarchies, flow graphs, packet length distributions plus several others. Also, many of these tools accepts Wireshark's filter syntaxis so the drill down you can make and the information you can extract from a pcap file is quite deep.
Solution 2
I just recently purchased Cascade Pilot, which is kind of spendy.
Author by
Flip
Updated on September 17, 2022Comments
-
Flip over 1 year
Does anyone knows a graphical tool to analyse wireshark captures?
Like something that can agregate traffic by ip's and by protocol and show's it graphicly.
Anyone knows a freeware/opensource utility?
Thanks
-
Admin about 13 yearsAre you trying to do this on the spot, or have a more permanent statistics-gathering setup?
-
Admin about 13 yearsI want to save a pcap, and then analyse it.
-
-
Flip about 13 yearsDoes it work won Windows? (win2008r2 / Win7)
-
Hyppy about 13 yearsMRTG would also work, using a relatively simple SNMP setup instead of a possibly awkward Netflow configuration.
-
mfinni about 13 yearsNetFlow is a protocol, like SNMP. You need to run Netflow collector software that is pointing at your network devices. There are netflow collectors that run on Windows, yes. SolarWinds Orion has a netflow component, there are others.
-
mfinni about 13 yearsHyppy- Can you actually get protocol-level information from SNMP? As requested, Flip wants IPs (doesn't specific source or destination) and protocol - presumably TCP/UDP port, again not specified but that's most common. How do you export or query that via SNMP? I didn't think you could, but if you know how, that would be great.
-
Hyppy about 13 yearsAhh you're right, no protocol information in SNMP that I know of, at least not without getting really dirty in the MIBs on a vendor-by-vendor basis :-/
-
Flip about 13 yearsThanks jliendo, i didn't saw that feature. That did it it's a very nice feature and it gives an idea of going overall.