How to Log Network Activity

How to Log Network Activity thumbnail
Logging Network Activity

Well-managed networks maintain logs of particular events. This information is important in order to determine such information as where e-mails are coming from, the IP addresses downloading files, login information as well as software installations on a network. These logs can be generated and kept by routers, gateway computers and even by workstations. A number of tools exist to log network activity. Microsoft Windows however comes with an inbuilt network logger called Port Reporter that not only logs network data but also logs opened connections and the processes using them. This tool can be used to analyze network traffic as well.

Instructions

  1. Installation

    • 1

      Visit the Microsoft Download Center page and download the Port Reporter tool (See Resources).

    • 2

      Download the Port Reporter Parser tool (See Resources). This tool is used to analyze the log files generated by the Port Reporter tool. Its many features that help to analyze the logs such as a Graphical User Interface (GUI), a filtering feature as well as a ranking feature based on process usage, IP addresses and port usage by the hour.

    • 3

      Run the setup program (Pr-Setup.exe) to install the Port Reporter when logged with Administrator privileges. After running the application, a registry sub-key will be added to the Windows registry and the Port Reporter service that is added to the Service Control Manager database. The default installation folder for the service can be referenced using the path below:

      Drive: \Program Files\PortReporter

    • 4

      Configure the Port Reporter service by going to "Start" and right-clicking "My Computer" "Manage." Under the "Services and Applications", select "Services." Verify on the listing that the Port Reporter service is listed. Click on "Start" to get it up and running.

    • 5

      Run the Port Reporter by extracting it onto your hard drive and running the "prpsetup.exe" file. Follow the wizard to complete the installation. Locate the log files to be viewed using the path below:

      Drive\System32\LogFiles\PortReporter

      Replace "Drive" with the appropriate local drive location.

Tips & Warnings

  • Once the Port Reporter service is installed, it is registered as a service and is therefore accessible under the Microsoft services. It can thus be run, stopped or disabled from this location.

  • Use the command prompt to install the service to a different location other than the default location using the following command line:

  • Pr-setup.exe --d 'PathOfFolder'

  • The "PathOfFolder" is the drive and path where the service is to be installed.

  • By default, the Port Reporter service does not start automatically when Windows starts. You need to change the settings to "Automatic" under "Services and Applications".

Related Searches:

References

Resources

  • Photo Credit computers network image by Orlando Florin Rosu from Fotolia.com

Comments

You May Also Like

Related Ads

Featured