How do I investigate traffic spikes?
Hi!
I'm not an experienced sysadmin, but if I know what to look for I will manage to Google.
I'm using Centminmod with Centos7 on Linode, and getting these emails about traffic spikes every few days. It's always ipv6. I'm wondering how can I investigate which URLs are they hitting/what is this thing in general?
screenshot of my Linode panel graphs: https://i.imgur.com/gJO6OLm.png
Thanks for any tips!
1 Reply
@vandelayed --
I'd have a look at the appropriate server logs and investigate activity based on the time of day.
If you find you have a problem with some kind of attack, setting up fail2ban(1) can probably mitigate it in short order. Setting up an iptables(8) block will mitigate it even faster.
-- sw