On Thu, 31 Aug 2006 22:07:10 +0000, RMK <(E-Mail Removed)> wrote:
>Then I realised that the noise was from the drive in my firewall.
...
>Anybody?
Timestamp filter: 12 hours from Sep 01 01:03:19 to Sep 01 13:03:19 (+1000)
Reading /var/log/messages
Checked 13819 records plus 0 repeats to find 453 from deltree.
Protocol summary: 374 UDP, 79 TCP
25/tcp 2 | . . . . 0.4
80/tcp 10 |(( . . . . 2.2
135/tcp 7 |( . . . . 1.5
137/udp 2 | . . . . 0.4
139/tcp 2 | . . . . 0.4
445/tcp 27 |((((( . . . . 6.0
1026/udp 208 |(((((((((((((((((((((((((((((((((((((( . 45.9
1027/udp 160 |(((((((((((((((((((((((((((((. . 35.3
1433/tcp 7 |( . . . . 1.5
2100/tcp 3 |( . . . . 0.7
3306/tcp 3 |( . . . . 0.7
4899/tcp 7 |( . . . . 1.5
8080/tcp 1 | . . . . 0.2
12879/tcp 2 | . . . . 0.4
40568/tcp 2 | . . . . 0.4
62559/tcp 3 |( . . . . 0.7
others 7 |( . . . . 1.5
total 453 + - - - - + - - - - + - - - - + - - - - + - - -
0 12.0% 24.0% 36.0% 48.0%
Classify junk:
371 drop msft messenger spam
30 drop adaptive deny, msft tcp
20 reject msft common ports, tcp
10 drop web crawler calming
10 reject junk, tcp
9 drop request from low port
2 drop msft common ports, udp
1 drop junk, other (policy)
Just the usual here

81% messenger spam...
Grant.
--
http://bugsplatter.mine.nu/