How do I investigate traffic spikes?

Hi!

I'm not an experienced sysadmin, but if I know what to look for I will manage to Google.

I'm using Centminmod with Centos7 on Linode, and getting these emails about traffic spikes every few days. It's always ipv6. I'm wondering how can I investigate which URLs are they hitting/what is this thing in general?

screenshot of my Linode panel graphs: https://i.imgur.com/gJO6OLm.png

Thanks for any tips!

1 Reply

@vandelayed --

I'd have a look at the appropriate server logs and investigate activity based on the time of day.

If you find you have a problem with some kind of attack, setting up fail2ban(1) can probably mitigate it in short order. Setting up an iptables(8) block will mitigate it even faster.

-- sw

Reply

Please enter an answer
Tips:

You can mention users to notify them: @username

You can use Markdown to format your question. For more examples see the Markdown Cheatsheet.

> I’m a blockquote.

I’m a blockquote.

[I'm a link] (https://www.google.com)

I'm a link

**I am bold** I am bold

*I am italicized* I am italicized

Community Code of Conduct