Linux Traffic Monitoring Tool-Iftop (the most comprehensive iftop tutorial)

Source: Internet
Author: User

In Unix-like systems, you can use top to view information such as system resources, processes, memory consumption, and so on. View network status You can use Netstat, nmap and other tools. To see real-time network traffic, monitor TCP/IP connectivity, and so on, you can use Iftop.

What is Iftop?

The iftop is a real-time traffic monitoring tool similar to top.

Official website:

Second, what is the use of iftop?

Iftop can be used to monitor the real-time traffic of the network card (can specify the network segment), reverse resolution of IP, display port information, etc., detailed will be described in the following usage parameters.

Third, installation Iftop installation Method 1,Compiling the installation

If the use of compiled installation can go to the Iftop official website to download the latest source package.

Pre-installation requires the installation of the necessary environment for the basic compilation, such as Make, GCC, autoconf and so on. Installing the Iftop also requires the installation of Libpcap and libcurses.

Install the required dependency packages on CentOS:

Yum Install Flex BYACC libpcap ncurses ncurses-devel libpcap-devel

Install the required dependency packages on Debian:

Apt-get Install Flex BYACC libpcap0.8 libncurses5

Download Iftop


Tar zxvf iftop-0.17.tar.gz

CD iftop-0.17


Make && make install

Installation Method 2: (Lazy way, the simplest)

Omit the above steps directly

CentOS System:

Yum Install Flex BYACC libpcap ncurses ncurses-devel


RPM-IVH iftop-0.17-1.el5.rf.i386.rpm

Debian system operation: Apt-get install Iftop

Four, running Iftop

Direct operation: Iftop

Effects such as:

650) this.width=650; "class=" Alignnone size-full wp-image-1407 "title=" Iftop-interface "src="/http "Width=" 646 "height=" 341 "/>

V. Relevant parameters and instructions 1, IFTOP interface related instructions

The interface above shows a scale range similar to that of the scale, which is used as a ruler for the bar showing the flow graph.

The <= in the middle and the two left and right arrows indicate the direction of the flow.

TX: Send Traffic
RX: Receive Traffic
Total: Overall flow
Cumm: Total traffic running iftop to current time
Peak: Traffic Peaks
Rates: Represents the average traffic for the past 2s 10s 40s, respectively

2. Parameters commonly used in iftop related parameters

-I set the monitoring network card, such as: # Iftop-i eth1

-B displays traffic in bytes (default is bits), such as: # Iftop-b

-N Causes the host information to display IP directly by default, such as: # Iftop-n

-N causes port information to be displayed by default directly, such as: # Iftop-n

-F shows incoming and outgoing traffic for a specific segment, such as # iftop-f or # iftop-f

-H (Display this message), Help, display parameter information

-p after using this parameter, the middle list shows the local host information, and the IP information outside of this machine appears;

-B to display the flow graph bar by default;

-F This is not very likely to use, filter the calculation of the packet;

-P enables host information and port information to be displayed by default;

-M sets the maximum value of the top-most scale of the interface, with a scale of five large segments, for example: # iftop-m 100M

Some operation commands after entering the Iftop screen (note case)

Press H to toggle whether help is displayed;

Press N to toggle the display of the IP or host name of the machine;

Press S to toggle whether the host information of the machine is displayed;

Press D to toggle whether the host information of the remote target hosts is displayed;

Press T to toggle the display format to 2 lines/1 lines/Only send traffic/show receive traffic only;

Press N to toggle display port number or port service name;

Press S to toggle whether to display the port information of the machine;

Press D to toggle whether the port information of the remote target host is displayed;

Press p to toggle whether the port information is displayed;

Press p to toggle pause/resume display;

Press B to toggle whether the average flow graph bar is displayed;

The average flow in 2 seconds or 10 seconds or 40 seconds is calculated by B switch;

Press T to toggle whether the total traffic for each connection is displayed;

Press L to turn on the screen filtering function, enter the characters to filter, such as IP, press ENTER, the screen will only show this IP-related traffic information;

Press L to toggle the scale on the top of the display screen, and the flow graph bar will change depending on the scale;

Press J or press K to scroll up or down the screen to display the connection record;

Press 1 or 2 or 3 to sort by the three-column traffic data displayed on the right;

Sort by < According to the native name or IP on the left;

Sort by > According to the host name or IP of the remote target host;

Press O to toggle whether the current connection is fixed only;

Press F to edit the filter code, this is translated by the saying, I have not used this!

You can use the shell command, this is useless! I don't know what the order is.

Press Q to exit the monitor.

Vi. FAQs

1, Make:yacc:Command not found
Make: * * * [GRAMMAR.C] Error 127

Workaround: Apt-get Install Byacc/yum install BYACC

2, configure:error:curses! Foiled again!
(Can ' t find a curses library supporting Mvchgat.)
Consider installing ncurses.

Workaround: Apt-get Install Libncurses5-dev/yum install Ncurses-devel

This article is from the "Tangjilinux" blog, make sure to keep this source

Linux Traffic Monitoring tool-Iftop (the most comprehensive iftop tutorial)

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.