Geek Pop Quiz.
May. 13th, 2009 04:13 pmI have a network.
I want to know who is surfing the web, to where, and, if possible, how long they spend doing it. With records and hopefully a nice happy interface where I can see "John refreshed livejournal.com, like, 40 times today"
What's the best way to set something up to monitor this?
Squid proxy with some kind of log reader? Got a link on how to set that up?
This is, right now, purely a "hmm, how can I do this?" exercise.
(Oh, and: I *can* block all traffic that doesn't go past my monitor, if I feel like it. So it's not like people can break my proxy by just removing it, if I go with a proxy.)
I want to know who is surfing the web, to where, and, if possible, how long they spend doing it. With records and hopefully a nice happy interface where I can see "John refreshed livejournal.com, like, 40 times today"
What's the best way to set something up to monitor this?
Squid proxy with some kind of log reader? Got a link on how to set that up?
This is, right now, purely a "hmm, how can I do this?" exercise.
(Oh, and: I *can* block all traffic that doesn't go past my monitor, if I feel like it. So it's not like people can break my proxy by just removing it, if I go with a proxy.)
(no subject)
Date: 2009-05-13 08:31 pm (UTC)(no subject)
Date: 2009-05-13 09:36 pm (UTC)(no subject)
Date: 2009-05-14 12:40 pm (UTC)(no subject)
Date: 2009-05-14 01:56 pm (UTC)(no subject)
Date: 2009-05-13 09:07 pm (UTC)(no subject)
Date: 2009-05-13 09:36 pm (UTC)(I have a snort box insystem already. I *could* have it log non-alerts on every bit of web traffic and parse those - but, again, PITA.)
(no subject)
Date: 2009-05-13 10:24 pm (UTC)(no subject)
Date: 2009-05-15 04:02 pm (UTC)(no subject)
Date: 2009-05-13 11:15 pm (UTC)(no subject)
Date: 2009-05-13 11:32 pm (UTC)(no subject)
Date: 2009-05-14 01:05 am (UTC)I seem to recall my old Windows 98 box, back in the days when everybody on campus was hooked into the network and sharing their media folders, had an application that showed who was connected to my computer and doing what in what folder.
(no subject)
Date: 2009-05-14 04:58 am (UTC)I'm suggesting splunk because I suspect you might be under the threshold of volume that would move you into the paying for it category :)
(no subject)
Date: 2009-05-14 08:31 pm (UTC)Paying for it: HOLY SHIT STARTS AT $15K!
(no subject)
Date: 2009-05-14 08:53 pm (UTC)