- May 3, 2005
- 1,065
- 0
- 71
So, I had a huge spike in network traffic last Friday that lasted nearly an hour and don't know where the hell it came from. I was at 40% network utilization with a teamed pair of 100 mbps nics so 80 mbps sustained traffic. Obviously this is too much to be coming over a broadband connection so I guess the Chinese are out, but I'm trying to figure out if a particular system on my LAN was the culprit. I've combed through all the logs I could find and done extensive googling but have yet to find any logs that show IP connections/activity at the time in question. Does such a log exist in Server 2003 by default or do I need to be running a special utility to capture this kind of info? This is not a web server so the web logs are useless. It's a DC which also serves as a print server and file server. Any help is greatly appreciated as for right now I don't have a good reason for the anomaly.
