check network suspicious_upload_vlan20 interface vtnet2 if total download > 2 GB in the last 1 hour then alert
# while true dodate;netstat -I vtnet2 -b | awk '/Link/{print "Uploaded by VLAN20: "$8/1024/1024 " MB"}'sleep 600 doneThu Jan 7 11:04:39 EST 2021Uploaded by VLAN20: 24254.7 MBThu Jan 7 11:14:39 EST 2021Uploaded by VLAN20: 24255.1 MBThu Jan 7 11:24:39 EST 2021Uploaded by VLAN20: 24255.5 MBThu Jan 7 11:34:39 EST 2021Uploaded by VLAN20: 24256 MBThu Jan 7 11:44:39 EST 2021Uploaded by VLAN20: 24256.5 MBThu Jan 7 11:54:39 EST 2021Uploaded by VLAN20: 24257 MBThu Jan 7 12:04:39 EST 2021Uploaded by VLAN20: 24257.4 MBThu Jan 7 12:14:39 EST 2021Uploaded by VLAN20: 24259.3 MBThu Jan 7 12:24:39 EST 2021Uploaded by VLAN20: 24277.6 MBThu Jan 7 12:34:39 EST 2021Uploaded by VLAN20: 24296.4 MBThu Jan 7 12:44:39 EST 2021Uploaded by VLAN20: 24313.5 MB
Download bytes exceeded Service suspicious_upload_vlan20 Date: Thu, 07 Jan 2021 12:11:58 Action: alert Host: OPNsense-primary.localdomain Description: total download 4.6 GB matches limit [download rate > 2 GB in last 1 hour]Your faithful employee,Monit