From owner-freebsd-questions@FreeBSD.ORG Thu Apr 15 21:01:33 2010 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id AE0E7106566B for ; Thu, 15 Apr 2010 21:01:33 +0000 (UTC) (envelope-from cswiger@mac.com) Received: from asmtpout030.mac.com (asmtpout030.mac.com [17.148.16.105]) by mx1.freebsd.org (Postfix) with ESMTP id 99DEE8FC1D for ; Thu, 15 Apr 2010 21:01:33 +0000 (UTC) MIME-version: 1.0 Content-type: text/plain; charset=utf-8 Received: from cswiger1.apple.com ([17.209.4.71]) by asmtp030.mac.com (Sun Java(tm) System Messaging Server 6.3-8.01 (built Dec 16 2008; 32bit)) with ESMTPSA id <0L0X002L3RQFTP30@asmtp030.mac.com> for freebsd-questions@freebsd.org; Thu, 15 Apr 2010 14:01:28 -0700 (PDT) X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 ipscore=0 phishscore=0 bulkscore=0 adultscore=0 classifier=spam adjust=0 reason=mlx engine=5.0.0-0908210000 definitions=main-1004150231 From: Chuck Swiger X-Priority: 3 In-reply-to: Date: Thu, 15 Apr 2010 14:01:27 -0700 Content-transfer-encoding: quoted-printable Message-id: References: To: =?utf-8?Q?Yavuz_Ma=C5=9Flak?= X-Mailer: Apple Mail (2.1078) Cc: freebsd-questions@freebsd.org Subject: Re: about tcpdump X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 15 Apr 2010 21:01:33 -0000 On Apr 15, 2010, at 1:37 PM, Yavuz Ma=C5=9Flak wrote: > I have a network. I wish to log all incoming and outgoing trafficc = using tcpdump on my gateway server. But I don't want to log these = traffic's data because of they take up much on disk. > I only want to log which ports were used, which ip addresses were = reached. > How can I do these using tcpdump ? "tcpdump -nq" will display a short and sweet summary of packets, without = the contents. You might also find that /usr/ports/net/tcpflow is = helpful for coalescing tcpdump data into flows. Regards, --=20 -Chuck