On Fri, Oct 2, 2026 at 3:14 PM chara <[email protected]> wrote: > > > Hello there. > > I have been running a public OpenBSD installation that offers various > services. > the installation has a quota on its upload/download and i'd like to know what > services (ports) have used the quota.
assuming you have pf rules for the ports already, each pf rule already records packets in and out. that can be extracted via a few means and recorded. > > I have looked into ifstat, vnstat and bwm-ng and all of them appear to be > able to only monitor per interface, not per port (at least on openbsd). > > You may make a virtual interface for each of the services, but apperently > vnstat and other programs are not able to get information of loop-backed > network I/O (i.e: when source and destination are on the same machine) > > Another solution is to capture a pcap on the interfaces with bpflogd > and do the processing afterwards, but this needs a fair amount to storage > to save the pcap (even if we only save until tcp headers) and processing power > to generate a report from. > > If you know of a program that solves the stated problem please let me know. > thanks a lot. > -- > chara <[email protected]> >

