From Newsgroup: alt.windows7.general
On Sat, 9/5/2026 11:15 AM, J. P. Gilliver wrote:
I have a network utility monitor that shows me when there is up- or
download traffic on my internet (wifi link). The one I use is BitMeter2,
but I imagine there are many such. It has an audio option - a beep every
x bytes up- or downloaded; I have this on (with x set to 100 kB). [Don't
use this unless you live alone - it irritates some people!]
I find it useful - to monitor things I've instigated such as downloads
(I get some idea of when they start and stop, and how fast the link is),
and also it tells me when something is unexpectedly down- or uploading.
When this latter happens, I'd like to know what is doing so. I normally expect Thunderbird, Edge, occasionally AVG, and Windows itself. I've
tried opening task manager and clicking on the Networking column to sort
by that, but that doesn't really tell me. (Also, if I was paranoid ... sometimes I think the burst of activity stops when I open task manager!
But I don't think that's really the case.)
What I'd like is something I could invoke - say from a pinned taskbar
thing - when there's a flurry, which would list what's using the link,
at a fairly high level, such as Thunderbird, Edge, AVG, etc., not down
to the sub-sub-sub-process level. Ideally, dynamic.
Suggestions? I do have the Nirsoft and Sysinternals suites (and the NirLauncher), and have tried a few likely-looking ones there, but they
were either not quite what I wanted, or gave too much information. But
one of those may be suitable and I just haven't picked the right one.
The thing is, the activity is fairly complex, for the human eye to eyeball,
and tools like this are "too much for a small screen". To use this to its
best extent, I would have to rotate a 4K screen into portrait mode so
I could see all of it. This shows when a connection is going through
its "2 minutes to oblivion" thing, the connection will change colour before
it disappears. The packets sent and received are necessary, to note whether there is currently traffic or not. This is "too busy" a display for
your purposes, you'd want a filtered version of this. But, we have to
include it, as it covers everyones tent.
https://learn.microsoft.com/en-us/sysinternals/downloads/tcpview
There are some FOSS things with names I can't remember, which produce a
similar output. Netstat ? Dunno. You can see where TCPView got its role model from.
https://www.geeksforgeeks.org/linux-unix/netstat-command-linux/
Wireshark can give a detailed trace. The Wireshark PCAP, feeding a program
you wrote your own self, could allow you to tailor the information gathered
a bit better. TCPView has too many "dead" or "inactive" things, to be an attractive summary (you can click the traffic column, to cause the busy connections to float to the top). The capture agent bundled with Wireshark,
on a Mac computer, would have a name other than winPCAP...
winPCAP ---- Wireshark display ---- <eyeballs>
winPCAP ---- <home brew prog> ---- <eyeballs> # You could use the captured packet stream
# to build your own summary. Remember, AI's write
# code, but you need a whip and chair to get a result.
Microsoft has their own version of Wireshark, and it is based on ETW packet capture. The Sysinternals Process Monitor, also had ETW network packets added to its trace, but not all my copies of that here, seem to have that, and
the reverse lookup doesn't work too well there (you see more akamai CDN references than should really be in such a trace). Depending on which
OS you're running, you may need an older version of some of the
Sysinternals ones, to support Windows 7. That means going to archive.org,
but the naming convention and URL is not consistent through the collection
for Sysinternals, so it can take a fair amount of "research" to guess
where a really old copy is hiding.
Naturally, a lot of the Microsoft activity is obfuscated. BITS or DoSVC
do downloads of stuff, and there is more than just Patch Tuesday going
through there. The items may have long numbers for names, so you
cannot see "hey, this is KB1234567 coming in". Or "hey, my Metro.Apps
are getting updated, that Teams I never use is updated again" :-)
Just because you have a "trace", does not mean as the administrator
of the machine, you get to find out what the traffic sink is.
Wouldn't it be nice if... never mind :-)
Paul
--- Synchronet 3.22a-Linux NewsLink 1.2