http://www.linuxplanet.com/linuxplanet/tips/1163/1
Quick and dirty net sniffingAnalyse tcpdump output with a perl "one liner"October 26, 1999
run
and then analyse the output: Do this repeatedly to see what is generating the traffic on your host's interface. Here is the same thing as a short script:
#!/usr/bin/perl -w
If you want something more sophisticated then the Ethereal package is worth a look. |