Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Somehow related - can't praise enough ntopng [1]. I've used it not only in the more traditional manner, as active traffic analysis, but also as forensic tool, by passing it traffic capture files, and obtaining clear relationships and contributing end points apps and security issues. Highly recommend it.

Edit: Forgot the nprobe [2] (same author), allowing flow data creation and export, expecially where L3 flow capable devices are not usable (e.g. intra-VLAN)

[1] https://www.ntop.org/products/traffic-analysis/ntop/

[2] https://www.ntop.org/products/netflow/nprobe/



It is especially great, because it allows fast analytics on historical data with ClickHouse: https://www.ntop.org/ntop/historical-traffic-analysis-at-sca...


Their website says it's GPL but I ran into some issue the last time I tried to try it out, it wanted a paid proprietary license or something?


Kind of an unfortunate name. At first I thought it was "NToPNG" and was slightly confused.


Nice


Just as a heads up if you wonder why your comment is gray and has a negative score.

HN really doesn't like or wants comments saying "agree", "nice", "+1" etc., because they add nothing to the conversation. Just upvote a comment/post if you agree or like it :)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: