# App to monitor source of network traffic

**URL:** <https://boards.straightdope.com/t/app-to-monitor-source-of-network-traffic/438218>\
**Category:** Factual Questions\
**Created:** [February 19, 2008, 5:39am UTC](https://boards.straightdope.com/t/app-to-monitor-source-of-network-traffic/438218 "2008-02-19T05:39:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![GuanoLad](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guanolad/32/42_2.png) [@GuanoLad](https://boards.straightdope.com/u/GuanoLad)\
**Post date:** [February 19, 2008, 5:39am UTC](https://boards.straightdope.com/t/app-to-monitor-source-of-network-traffic/438218/1 "2008-02-19T05:39:41Z")

</div>

I know there are applications that measure network traffic in kbps, and can gather statistics thereof. I have one running.

But I would like to know if there’s one that will tell me where this traffic is originating; what application is using the network; where it is downloading from or uploading to; and whether it’s over the internet or through my internal network.

I can’t seem to locate something that does this, and it surprises me as it sounds like something that would be sought after and very popular.

I’m using Windows XP Pro, SP2.

---

<div class="post-metadata">

**Author:** ![Mike.V](https://avatars.discourse-cdn.com/v4/letter/m/82dd89/32.png) [@Mike.V](https://boards.straightdope.com/u/Mike.V)\
**Post date:** [February 19, 2008, 7:40am UTC](https://boards.straightdope.com/t/app-to-monitor-source-of-network-traffic/438218/2 "2008-02-19T07:40:02Z")

</div>

TCPView will show you the local and remote addresses of all TCP connections on your Windows computer. I find it very helpful for this sort of thing.

> **[TCPView for Windows - Sysinternals](https://learn.microsoft.com/en-us/sysinternals/downloads/tcpview)**
>
> Active socket command-line viewer.

---

<div class="post-metadata">

**Author:** ![Kyrie\_Eleison](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/kyrie_eleison/32/7682_2.png) [@Kyrie\_Eleison](https://boards.straightdope.com/u/Kyrie_Eleison)\
**Post date:** [February 19, 2008, 7:42am UTC](https://boards.straightdope.com/t/app-to-monitor-source-of-network-traffic/438218/3 "2008-02-19T07:42:54Z")

</div>

I’m a Unix/Linux guy mostly, so I’m not likely to be aware of any useful Windows-specific tools. However, I’m aware than one of the most popular GUI-based protocol analyzers under Linux is (or at least used to be) [Ethereal](http://www.ethereal.com/), and that there’s a Windows port of it.

This is a tool that will allow you to examine network traffic in detail. From your description, it sounds like you may be looking for something that offers a more comprehensive examination of your network traffic. This isn’t that, last time I looked, but it’s something that, with a little work, might allow you to get there.

FWIW, I usually use tcpdump for such tasks – a fact offered because I figure that knowing the name of it might allow you to more easily search for Windows analogs.

I’ve mentioned only freely available software; there are many companies out there who will be happy to sell you commercial protocol analyzers, with a variety of features, if that’s what you’re looking for.

---

<div class="post-metadata">

**Author:** ![GuanoLad](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guanolad/32/42_2.png) [@GuanoLad](https://boards.straightdope.com/u/GuanoLad)\
**Post date:** [February 19, 2008, 8:19am UTC](https://boards.straightdope.com/t/app-to-monitor-source-of-network-traffic/438218/4 "2008-02-19T08:19:10Z")

</div>

[QUOTE=Mike.V]  
TCPView will show you the local and remote addresses of all TCP connections on your Windows computer. I find it very helpful for this sort of thing.  
[/QUOTE]  
After further investigation I found things called Packet Sniffers that seemed to be what I was looking for (like Ethereal, or the Windows spin-offs like Wireshark), but I have tried this TCPView first and it’s pretty good. It seems to be a more advanced version of what you can get on the Task Manager, pretty much what I wanted, though not _entirely_ comprehensible to a layman like me.

Thanks. I await any further suggestions.

---

<div class="post-metadata">

**Author:** ![Hodge](https://avatars.discourse-cdn.com/v4/letter/h/5f9b8f/32.png) [@Hodge](https://boards.straightdope.com/u/Hodge)\
**Post date:** [February 19, 2008, 4:10pm UTC](https://boards.straightdope.com/t/app-to-monitor-source-of-network-traffic/438218/5 "2008-02-19T16:10:12Z")

</div>

redundant post.
