If there's only ONE person who contacted the particular host, then the data should be in the rrd database (if you've enabled that plugin). You can extract it into a spreadsheet and manipulate it however you want.
If you need to preserve information longer, look into the sticky-hosts option (man ntop), but to retain sessions longer, you'll need to adjust the purge intervals - see globals-defines.h -----Burton > -----Original Message----- > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of > Michael Gale > Sent: Wednesday, January 14, 2004 11:28 AM > To: [EMAIL PROTECTED] > Subject: [Ntop] NTOP and internal host received from ? > > > Hello, > > I am running slackware 9.1 with ntop-current (ntop-04-01-12), please > let me know if you need any other info. > > I am running ntop on a firewall with 4 interfaces and am only monitoring > the DMZ and internal NIC. I want to be able to track user activity. > Every one has a static IP on the inside (10.10.X.X) > > I started NTOP with: > > ntop -4 --daemon -g -i eth1,eth2 -o -n -p userprolist -s -u ntopwatch -w > IP:3000 -D domain.com -M -O /home/ntopwatch/ -P /home/ntopwatch/ > > It is working great but when I click on a internal IP I can see that > this person downloaded 193MB over http since Sunday night. > > At the bottom of the page I can see what hosts they have recently been > connected too but is there any way to find out how much they downloaded > from each external host ? > > I click on the host IP but get a error page because that host does not > exist. Is this because used the -g option to track local hosts only ? > > -- > Michael Gale > Network Administrator > Utilitran Corporation > _______________________________________________ > Ntop mailing list > [EMAIL PROTECTED] > http://listgateway.unipi.it/mailman/listinfo/ntop > _______________________________________________ Ntop mailing list [EMAIL PROTECTED] http://listgateway.unipi.it/mailman/listinfo/ntop
