I searched a lot but I don't find a solution. I would to know if it is possible in tshark to filter the traffic (in Bytes) for each mac address
I have started something like this :
Any idea please ?
Thank you so much for your quick response !! I will try this tomorrow.
Another question : My goal is to detect abnormal traffic volume during the night (virus...) I do not necessarily know all the mac address as they connect to wifi
so is it possible to combine the data volume per mac address without knowing them ?
something like this :
thank you again kevin
answered 02 Mar '11, 09:38
To see all ethernet conversations use:
answered 02 Mar '11, 10:41