eth0 log

tony.chamberlain at tony.chamberlain at
Fri Feb 8 13:28:26 UTC 2008

We have a centos machine that apparently tried to send 3 G of data
over the internet (inside a VPN) in a short period of time. We were
asked to investigate. I looked where I could (/var/log/messages
and catalina.out) but didn't see anything.

Is there any sort of eth0 log? Any other way to try to figure out what
was sending out so much data?

Also, any way to turn on Wireshark in the background or something?
(For future).

