I want to record all network activity of one device to a USB flash drive.
In fact, I would like to know what IPs it connects to and what ports are used.
Have you guys already done it before ?
Can you help me ?
Here is what I think I should do :
Activate the log of the zone in which the device is located, isn't it ?
Install tcpdump
Script : tcpdump command that logs the activities of the device
In fact, it's complicated to visualize well in a shell.
I would like to take the logs and visualise it on my computer in a Excel table or another program that can put it in a table so I can filter and visualize the needed lines.
Do you know how I can manage to do that ?
your pc the traffic is mirrored to has to be on all the time
(so may or may not be suitable for long term use depending on your environment, if not see adblock for tcpdump header only capture to file)
does not currently support ipv6 or concurrent dual stack capture ( i have a hack for the former if you need it, and would only take a line or two so support the latter )