check incoming http traffic linux

netstat -an | grep 80
netstat -an | grep 443
tcp      126      0 0.0.0.0:443             0.0.0.0:*               LISTEN
tcp        0      0 143.110.178.90:443      205.253.121.153:52152   SYN_RECV
tcp        0      0 143.110.178.90:443      152.57.192.63:47054     SYN_RECV
tcp        0      0 143.110.178.90:443      27.56.249.178:10808     SYN_RECV
tcp        0      0 143.110.178.90:443      157.35.43.198:1372      SYN_RECV
tcp        0      0 143.110.178.90:443      47.9.172.31:55870       SYN_RECV
tcp        0      0 143.110.178.90:443      117.98.32.131:10813     SYN_RECV
tcp        0      0 143.110.178.90:443      132.154.33.245:33624    SYN_RECV
tcp        0      0 143.110.178.90:443      47.247.212.210:41872    SYN_RECV
tcp        0      0 143.110.178.90:443      49.35.235.170:42656     SYN_RECV
tcp        0      0 143.110.178.90:443      47.9.115.249:39206      SYN_RECV
tcp        0      0 143.110.178.90:443      106.207.92.249:57362    SYN_RECV
tcp        0      0 143.110.178.90:443      117.98.32.131:14891     SYN_RECV
tcp        0      0 143.110.178.90:443      132.154.107.193:39680   SYN_RECV
tcp        0      0 143.110.178.90:443      47.9.172.31:55880       SYN_RECV
tcp        0      0 143.110.178.90:443      157.38.0.56:38362       SYN_RECV
tcp        0      0 143.110.178.90:443      139.167.233.133:54550   SYN_RECV
tcp        0      0 143.110.178.90:443      117.233.103.181:18346   SYN_RECV
tcp        0      0 143.110.178.90:443      157.38.134.214:40246    SYN_RECV
tcp        0      0 143.110.178.90:443      117.201.66.45:56176     SYN_RECV
tcp        0      0 143.110.178.90:443      157.35.76.55:53226      SYN_RECV
tcp        0      0 143.110.178.90:443      157.32.245.96:37935     SYN_RECV
tcp        0      0 143.110.178.90:443      47.9.115.249:39326      SYN_RECV
tcp        0      0 143.110.178.90:443      47.15.154.160:57678     SYN_RECV
tcp        0      0 143.110.178.90:443      152.57.192.63:47060     SYN_RECV
tcp        0      0 143.110.178.90:443      49.42.75.8:49188        SYN_RECV
tcp        0      0 143.110.178.90:443      49.15.183.34:63883      SYN_RECV
tcp        0      0 143.110.178.90:443      157.34.199.240:38078    SYN_RECV
$ w
$ sar -u 5
$ ps -eo s,user | grep ^[RD] | sort | uniq -c | sort -nbr | head -20


Leave a Reply