Sniffnet – Comfortably monitor your internet traffic (like Wireshark)
sniffnet.net
sniffnet.net
Netflow gives you protocol types, src/dst ip & port, packet & byte counts, qos/tos, and more - much more cheaply than pcapping an interface. All SME and up gear support them, even Unifi USG's will eject NetFlows.
I'm a bit jaded about some of the free tooling these days though. Weirdly it feels like we've taken a step back the past several years - but for anything beyond 'I wonder who this one computer is talking to' they're a much better approach.
Rob did a big rewrite about 4 years ago, I think, licensing the new codebase in a way that led us to look elsewhere.
There's some alternatives that aren't elastic under the hood, of course. The hard-to-type Akvorado looks very promising, especially given its heritage:
https://github.com/akvorado/akvorado
Because we're moving to opentel / prometheus, this project (seems quite active) is especially interesting, with the promise of integrating OS & app metrics, tracing, and netflow insights:
But the high bit is of course that it's a self-contained normal app and just works.
(And it actually exists unlike the hypothetical netflow version.)
I'd argue your advantages perhaps - you do need local root, or at least net_admin / net_raw (I haven't looked to see if TFA drops all but these - perhaps you have?) which raises some security questions. In Linux you may also hit some challenges with promiscuous mode, or capturing on wireless interfaces.
The 'energy' to configure netflow is probably comparable to that required to install and configure this tool. If you don't have the feature on your network hardware, then, yeah, sure, it's moot.
I accept that this, and other existing tools, that let you correlate local processes with local network interface activity can be useful. In my experience it's rare to have to dive into that level, but definitely handy.
In a previous life I would frequently be flipping between Wireshark and Riverbed's Packet Analyzer (nee Pilot) which gives a higher level view than Wireshark. It feels like Sniffnet is aiming to be more in this category, so it's great to have a free software alternative.
For traffic that doesn't traverse routers, you may not know that switches can send netflow. Also, your favourite GNU/Linux distro can send flows.
> (And it actually exists unlike the hypothetical netflow version.)
I don't get this bit.
Are you asserting that netflow monitoring tools don't exist?
If you just want the general characterization of your data, then they are ok.
If you want to see every connection you certainly can use netflow, just means you need to spec out your solution properly - and if you've got a lot of chatty traffic it may get expensive.
Obviously much less expensive than interface capture approaches like TFA - plus netflows will typically come from your routing infrastructure.
EDIT: Apologies, I had not really processed the implications of 'if you want to see every packet'. Yes, you're right, but netflow was never about seeing every packet, but tracking every flow (which IIRC is usually defined as src/dst addr+port + protocol) - which will include a running total of bytes/packets over time, so it's counting every packet, but certainly not inspecting every packet, at least not in a DPI sense.
Netflow will inspect every connection as it's established, and then track it until it's torn down. This is one of the reasons netflow, and especially sampled netflow, can report really skewed results against long-lived connections - think Citrix, f.e.
Now if you actually care about per packet statistics rather than per flow statistics you'd want pcap. The more the world becomes encrypted the less interesting the actual packets become.
That's not 100% accurate.
Netflow v5, v9, and IPFIX all support (for at least a decade) sampling, and depending on vendor that'll be random, time, or packet-count, based).
No, irony left aside. I also miss the clean, boring but highly useful landing pages of old-school utility programs. A short description and a well written man page was all we needed, plus some screenshots for TUI/GUI programs.
My feeling is that especially Rust enthusiasts like emoji, colors and banners a lot. But maybe I am also just getting old...
Edit: HN did not like my emoji.
Have you tried finding a way to get your OS to supply you with the total list of emojis? That's the only thing I'd try to improve after I took a quick look.
I thought it was a great readme. It is weird how you guys dismissed the whole thing just because the readme has emojis.
Example at [1]. I can take this and run with it, after reading for less than 15 seconds I know enough to start working.
However Npcap's free edition is limited to 5 installations, with unlimited installations only allowed when used with Nmap, Wireshark, and/or Microsoft Defender for Identity [1]. Anything beyond that requires a license.
I'm not sure if that's problematic. Sniffnet don't distribute Npcap themselves so they're ok, I guess, but they do require their users to install it on Windows . So I guess this means that for private use someone can install Sniffnet + Npcap on up to 5 computers, but organizations with Windows systems cannot use Sniffnet + Npcap unless they buy Npcap's license.
[0] https://github.com/GyulyVGC/sniffnet#required-dependencies
Not OP, but here's a Google employee explaining why one would want to decrypt traffic.
https://web.archive.org/web/20220813220108if_/https://medium...
More from F5.
The cargo install is currently borked but the prebuilt bin works fine.
ntopng (https://www.ntop.org/products/traffic-analysis/ntop/) is much more featureful than sniffnet, works also with netflow and has seen multiple production deployments, monitoring 100Gbps flows at full rate.