Engineering Leader · Private Pilot · Dad · PSU Hockey
OAT 72° XPDR 1200 GS 145 18:42Z
10
20
10
20
160150140130120110100
138
32003100300029002800
3,000
306090120150
90
My Life
Bio & background
PROFILE · SET
My Computers
Current rigs
UPTIME · 100%
My Projects
What I'm building
STATUS · ACTIVE
Résumé
Curriculum vitae
FORMAT · HTML

Chasing a ghost

05/24/06 @ 5:49 pm · By Steve Hoffman · Comments (3) · Leave one
I spend two and a half hours last night chasing a ghost in our system... a larger customer of ours swore the system was not working at 10:30pm and he was so mad and going to leave us...blah blah blah.  Well I got on the system last night at 9:00pm and started gathering data...and about 45 minutes later, Rama got on as well...and started gathering data too.  So we checked everything...application servers, database servers, web servers, load balancers, internet throughput...nothing indicated there was the hint of a problem....this was of course backed up by our investigating of the logs which again showed no errors or anything to indicate there was a problem.  I've got two servers that monitor our application and if there's any problems with connecting I'll know in a matter of minutes.  I was able to employ a technique known as port cloning, which is a feature of the more advanced switches and routers.  So with cloning the port that dumps off to the internet I am able to connect that to a Linux server, put the interface in promiscuous mode and use several great tools to track down bandwidth consumption.  My favorite is iptraf, which will show me all the connections...allow me to sort by consumption and see what ports and IP's things are happening on.  I've used this technique in the past, but didn't have to clone the port on the switch because the network gateway was a Linux server so I just ran iptraf right there and could see the comings and goings...but now I can see EVERYthing.  Last week we had a bandwidth hog that was killing our bandwidth and it allowed me to track him down in less then a minute...I got the machine and closed the app that was doing it and once again..saved the day...damn I'm good!

Comments

??? · 05/25/06 @ 1:22 am · AP
Can you repeat that in English, please? Southern, too, while you're at it!
Hmmm... · 05/25/06 @ 1:40 pm · Steve
Translating to english is hard enough..but southern also... <p>Y'know how that there prezee-dent is spy'in on all them alkidee folks, I dun got the pow'r ta do it m'self only on them new fangled pewter's. I splice into the line kinda like stealin' cable from the folks next door and just watch whatever I want to.</p> <p>There may be more redneck in there then southern..but I think you'll get the point. Basically what I said was I can tap internet connection and see how much is coming and going...so long as it's not a secure site (https://) then I can even see what you're actually sending back and forth (read IM conversations, see the text of websites, tell what music file you're downloading etc). The only requreiment is that I have access to the cable that actually goes to the internet.
· 05/25/06 @ 2:33 pm · AP
Yeehaw! I done got it now!