Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations derfloh on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Log Files

Status
Not open for further replies.

paulha

Technical User
Joined
Oct 25, 2001
Messages
605
Location
GB
Afternoon Everyone

Our Proxy 2 logs are showing some strange activity at times when there should be nobody logged on, never mind accessing the internet.

Logic suggests spyware or virus activity, although I am convinced we are clear of both.

Is there any way of tracing the source of these internet sessions ? Only when authenticated users access via the proxy server do I get an IP Address logged.

Sample of log :

-, -, -, N, 5/28/2005, 3:41:49, 1, -, -, -, 80, 141, 1542, 172, http, tcp, -, -, VCache, 304, 18874368
-, -, -, N, 5/28/2005, 3:41:50, 1, -, -, 64.4.55.109, -, 80, 375, 961, 138, http, -, -, -, Inet, 200, 27262976
-, -, -, N, 5/28/2005, 3:41:50, 1, -, -, 64.4.55.109, -, 80, 391, 717, 140, http, tcp, -, -, Inet, 200, 27262976
-, -, -, N, 5/28/2005, 3:41:50, 1, -, -, 64.4.55.109, -, 80, 391, 572, 152, http, -, -, -, Inet, 200, 27262976
-, -, -, N, 5/28/2005, 3:41:50,


Thanks in advance

Paul
 
Hi, this is active caching activity. Note the absence of user name, computername, user agent.

Nothing to bother with. It's the automatic cache refresh.

This is made during idle hours.



Hope this helps. Please let me know if this resolve your issue

Jeff
 
Thanks for the tip

Paul
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top