---
title: 'Darkstat packet sniffer'
url: 'https://ra1ahq.blog/en/paketnyi-sniffer-darkstat'
markdown: 'https://ra1ahq.blog/en/paketnyi-sniffer-darkstat.md'
lang: en
date: '2024-02-28'
description: 'Darkstat is a free cross-platform network tool for collecting and viewing statistics on local network usage. Introd'
taxonomy:
  category:
    - blog
  tag:
    - Linux
  archives_month:
    - feb_2024
  archives_year:
    - '2024'
---

# Darkstat packet sniffer

28 

 February 

 2024 

 ![Darkstat packet sniffer](https://ra1ahq.blog/images/e/f/e/1/a/efe1a5f14851adface7a01461b388c059309524a-darkstat1.png)17:07

### Darkstat packet sniffer

 [Linux](https://ra1ahq.blog/en/tag:Linux) 

28 February 2024 17:07

Darkstat is a free cross-platform network tool for collecting and viewing statistics on local network usage.

### Introduction

When using a local network, it is sometimes useful to know about what is happening in it as a whole, in order to identify the full picture:

- abnormal increase in traffic (large volumes of transmission or reception, requests with high frequency)
- manifestation of new, unauthorized PCs or other people's devices on the local network
- troubleshooting (for example, requests to a specific port or protocol without a response).
- the appearance of non-standard protocols or opening of ports on local PCs (can be caused by malware).

It is advisable to do all this in the long term (24/7) and 365 days a year.

Since specialized software and hardware are not available and are not needed for amateur purposes, simpler solutions are used. For example, there is **darkstat**- network [traffic analyzer (sniffer)](https://ru.wikipedia.org/wiki/%D0%90%D0%BD%D0%B0%D0%BB%D0%B8%D0%B7%D0%B0%D1%82%D0%BE%D1%80_%D1%82%D1%80%D0%B0%D1%84%D0%B8%D0%BA%D0%B0).

Darkstat, unlike professional network tools such as Wireshark or tcpdump, does not capture entire network packets, but only looks at the packet headers. Darkstat uses a system library written in C++ that runs in the Linux kernel. Therefore, darkstat is undemanding to PC resources (CPU load less than 1%, RAM consumption no more than 1.7 MB).

**The Darkstat application consists of two parts:**

- a service that constantly runs in the background, capturing and collecting data into its database (DB).
- web interface at <http://localhost:667>..

### Darkstat features

- intercepting local network traffic using the libpcap kernel library
- entering abbreviated information (source IP/MAC receiver, ports, protocol) into your database (in the /var/lib/darkstat folder)
- the following options are available in the web interface:
- counting of packets seen and captured and traffic volume
- bookmark **graphs**= graphs of received/transmitted packets - by seconds, minutes, days and hours, indicating speed
- bookmark **hosts**- detailed information for each IP address
- counting the number of host packets by port: netbios-dgm, netbios-ns and bootps
- counting the number of host packets by protocol (TCP, UDP, ICMP, IGMP, GRE)
- IP addresses in the database are asynchronously converted into names for convenient presentation when displayed on the screen.
- IPv6 protocol support, TCP.UDP support, multicast and other protocols (netbios, HIP, DNS mDNS).

### Installing Darkstat

The libpcap traffic capture library is included in the Linux kernel and does not require installation.

Installation for various OS:

Ubuntu/XUbuntu/Linux Mint

```
sudo apt install darkstat
```

Debian:
su -
apt install darkstat

Fedora:

```
sudo dnf install darkstat
```

CentOS

```
sudo yum install darkstat
```

### Setting up darkstat

The configuration is in the file `/etc/darkstat/init.cfg`. It requires improvement before launch.
Here are the significant lines in the configuration file:

```
sudo nano /etc/darkstat/init.cfg
```

```
START_DARKSTAT=yes
INTERFACE="-i enp1s10" 
DIR="/var/lib/darkstat" 
DAYLOG="--daylog darkstat.log"
```

where:
START\_DARKSTAT - the value must be set to **“yes”**
**-i enp1s10**- name of the network card interface (you can find out with the command `ip addr`). If you do not specify or incorrectly set the INTERFACE parameter, then darkstat will not be able to listen to packets (it will not be able to work).
**"/var/lib/darkstat"**- working directory (by default, should not be changed). It will also store the database and the program start/stop log.
**--daylog darkstat.log**- file name for recording program starts/stops (located in the working directory).

### Launching Darkstat

On Ubuntu/Debian and MX Linux with SystemD launch system:

```
sudo systemctl start darkstat
sudo /lib/systemd/systemd-sysv-install enable darkstat
sudo systemctl status darkstat
```

In antiX or if in MX Linux [selected](https://mxlinux.org/wiki/system/systemd/) sysV initialization system instead of SystemD:

```
sudo /etc/init.d/darkstat start
sudo chkconfig darkstat on
sudo /etc/init.d/darkstat status
```

### Web interface

To open access to statistics from other PCs on the network, you need to configure the "uwf" firewall

```
sudo ufw allow 667/tcp
sudo ufw reload
```

To *close* access from other PCs to this computer via the darkstat port **667**:

```
sudo ufw deny 667/tcp
sudo ufw reload
```

To view the web interface, go to the address. No username or password required

<http://localhost:667>

### Related publications

 [ ![](https://ra1ahq.blog/images/f/3/a/2/c/f3a2c07ef5b32c0308ab703405a5a5ca87b75283-archer-ac600-728.webp) Установка драйвера ядра для Wi-Fi адаптера TP-Link после обновления ОС Debian ](https://ra1ahq.blog/en/ustanovka-draivera-yadra-dlya-wi-fi-adaptera-tp-link-posle-obnovleniya-os-debian) 

 [ ![](https://ra1ahq.blog/images/d/2/5/c/7/d25c7282750b398f71041fb8b90640b692e7e4b8-decibelfmtitle.png) Linux Cinnamon Desktop Applets for Listening to Internet Radio Stations ](https://ra1ahq.blog/en/applety-dlya-rabochego-stola-linux-cinnamon-dlya-proslushivaniya-internet-radiostancii) 

 [ ![No picture](https://ra1ahq.blog/user/themes/mytheme/images/no-image.png) Passing a parameter to a Linux module/driver ](https://ra1ahq.blog/en/peredacha-parametra-modulyu-draiveru-linux) 

 [ ![](https://ra1ahq.blog/images/5/c/4/e/a/5c4ea9c8c3f0b4dd890116d8fe7cbadfdb9814ba-archer-ac600.webp) Installing the TP-Link Archer T600U Nano Wi-Fi adapter driver in Debian 13 "Trixie" ](https://ra1ahq.blog/en/ustanovka-draivera-wi-fi-adaptera-tp-link-archer-t600u-nano-v-debian-13-trixie) 

 [ ![](https://ra1ahq.blog/images/b/f/f/0/f/bff0f99f5897e0420fac9a6eef7254247f39c29d-pulseaudio-equalizer.png) Installing the audio equalizer pulseaudio-equalizer-ladspa on Linux ](https://ra1ahq.blog/en/ustanovka-v-linux-ekvalaizera-zvuka-pulseaudio-equalizer-ladspa) 

[ Backward](https://ra1ahq.blog/en/optimizaciya-proizvoditelnosti-mozilla-firefox-chast-2 "Previuous page")

[ Forward ](https://ra1ahq.blog/en/zapusk-wireshark-bez-sudo-i-organizaciya-kolcevogo-bufera-zakhvata "Next page")

## Languages

- [Русский](https://ra1ahq.blog/posts/paketnyi-sniffer-darkstat)
- [English](https://ra1ahq.blog/en/paketnyi-sniffer-darkstat)
- [Deutsch](https://ra1ahq.blog/de/posts/paketnyi-sniffer-darkstat)
- [Français](https://ra1ahq.blog/fr/posts/paketnyi-sniffer-darkstat)
- [中文 (简体) (cn)](https://ra1ahq.blog/zh-cn/posts/paketnyi-sniffer-darkstat)

## Theme

## RSS feeds

 [ Atom 1.0](https://ra1ahq.blog/en/.atom) [ RSS](https://ra1ahq.blog/en/.rss) 

## Popular tags

 [APRS](https://ra1ahq.blog/en/tag:APRS) [CW](https://ra1ahq.blog/en/tag:CW) [DX](https://ra1ahq.blog/en/tag:DX) [FM](https://ra1ahq.blog/en/tag:FM) [Linux](https://ra1ahq.blog/en/tag:Linux) [VHF](https://ra1ahq.blog/en/tag:VHF) [antennas](https://ra1ahq.blog/en/tag:antennas) [firefox](https://ra1ahq.blog/en/tag:firefox) [morse](https://ra1ahq.blog/en/tag:morse) [soundtrack](https://ra1ahq.blog/en/tag:soundtrack) [video](https://ra1ahq.blog/en/tag:video) [windows](https://ra1ahq.blog/en/tag:windows) [youtube](https://ra1ahq.blog/en/tag:youtube) [КВ](https://ra1ahq.blog/en/tag:%D0%9A%D0%92) [ТВ](https://ra1ahq.blog/en/tag:%D0%A2%D0%92) [УКВ](https://ra1ahq.blog/en/tag:%D0%A3%D0%9A%D0%92) [антенны](https://ra1ahq.blog/en/tag:%D0%B0%D0%BD%D1%82%D0%B5%D0%BD%D0%BD%D1%8B) [безопасность](https://ra1ahq.blog/en/tag:%D0%B1%D0%B5%D0%B7%D0%BE%D0%BF%D0%B0%D1%81%D0%BD%D0%BE%D1%81%D1%82%D1%8C) [длинные волны](https://ra1ahq.blog/en/tag:%D0%B4%D0%BB%D0%B8%D0%BD%D0%BD%D1%8B%D0%B5%20%D0%B2%D0%BE%D0%BB%D0%BD%D1%8B) [путешествия](https://ra1ahq.blog/en/tag:%D0%BF%D1%83%D1%82%D0%B5%D1%88%D0%B5%D1%81%D1%82%D0%B2%D0%B8%D1%8F) [религия](https://ra1ahq.blog/en/tag:%D1%80%D0%B5%D0%BB%D0%B8%D0%B3%D0%B8%D1%8F) [соревнования](https://ra1ahq.blog/en/tag:%D1%81%D0%BE%D1%80%D0%B5%D0%B2%D0%BD%D0%BE%D0%B2%D0%B0%D0%BD%D0%B8%D1%8F) [спутники](https://ra1ahq.blog/en/tag:%D1%81%D0%BF%D1%83%D1%82%D0%BD%D0%B8%D0%BA%D0%B8) [средние волны](https://ra1ahq.blog/en/tag:%D1%81%D1%80%D0%B5%D0%B4%D0%BD%D0%B8%D0%B5%20%D0%B2%D0%BE%D0%BB%D0%BD%D1%8B) [схемы](https://ra1ahq.blog/en/tag:%D1%81%D1%85%D0%B5%D0%BC%D1%8B) [тесты](https://ra1ahq.blog/en/tag:%D1%82%D0%B5%D1%81%D1%82%D1%8B) [трансивер](https://ra1ahq.blog/en/tag:%D1%82%D1%80%D0%B0%D0%BD%D1%81%D0%B8%D0%B2%D0%B5%D1%80) [управление](https://ra1ahq.blog/en/tag:%D1%83%D0%BF%D1%80%D0%B0%D0%B2%D0%BB%D0%B5%D0%BD%D0%B8%D0%B5) [фотографии](https://ra1ahq.blog/en/tag:%D1%84%D0%BE%D1%82%D0%BE%D0%B3%D1%80%D0%B0%D1%84%D0%B8%D0%B8) 

## Random post

 [ I'll be lucky!](https://ra1ahq.blog/en/random) 

## Archive of posts

- [ October 2026 ✒ 4 ](https://ra1ahq.blog/en/archives_month:oct_2026)
- [ September 2026 ✒ 9 ](https://ra1ahq.blog/en/archives_month:sep_2026)
- [ August 2026 ✒ 6 ](https://ra1ahq.blog/en/archives_month:aug_2026)
- [ July 2026 ✒ 13 ](https://ra1ahq.blog/en/archives_month:jul_2026)
- [ June 2026 ✒ 8 ](https://ra1ahq.blog/en/archives_month:jun_2026)
- [ May 2026 ✒ 2 ](https://ra1ahq.blog/en/archives_month:may_2026)
- [ April 2026 ✒ 6 ](https://ra1ahq.blog/en/archives_month:apr_2026)
- [ March 2026 ✒ 3 ](https://ra1ahq.blog/en/archives_month:mar_2026)
- [ February 2026 ✒ 7 ](https://ra1ahq.blog/en/archives_month:feb_2026)
- [ January 2026 ✒ 8 ](https://ra1ahq.blog/en/archives_month:jan_2026)
- [ December 2025 ✒ 12 ](https://ra1ahq.blog/en/archives_month:dec_2025)
- [ November 2025 ✒ 9 ](https://ra1ahq.blog/en/archives_month:nov_2025)
- [ October 2025 ✒ 8 ](https://ra1ahq.blog/en/archives_month:oct_2025)
- [ September 2025 ✒ 5 ](https://ra1ahq.blog/en/archives_month:sep_2025)
- [ August 2025 ✒ 8 ](https://ra1ahq.blog/en/archives_month:aug_2025)
- [ July 2025 ✒ 6 ](https://ra1ahq.blog/en/archives_month:jul_2025)
- [ June 2025 ✒ 10 ](https://ra1ahq.blog/en/archives_month:jun_2025)
- [ May 2025 ✒ 4 ](https://ra1ahq.blog/en/archives_month:may_2025)
- [ April 2025 ✒ 4 ](https://ra1ahq.blog/en/archives_month:apr_2025)
- [ March 2025 ✒ 4 ](https://ra1ahq.blog/en/archives_month:mar_2025)
- [ February 2025 ✒ 11 ](https://ra1ahq.blog/en/archives_month:feb_2025)
- [ December 2024 ✒ 8 ](https://ra1ahq.blog/en/archives_month:dec_2024)
- [ November 2024 ✒ 2 ](https://ra1ahq.blog/en/archives_month:nov_2024)
- [ October 2024 ✒ 8 ](https://ra1ahq.blog/en/archives_month:oct_2024)
- [ September 2024 ✒ 3 ](https://ra1ahq.blog/en/archives_month:sep_2024)
- [ August 2024 ✒ 5 ](https://ra1ahq.blog/en/archives_month:aug_2024)
- [ July 2024 ✒ 9 ](https://ra1ahq.blog/en/archives_month:jul_2024)
- [ June 2024 ✒ 6 ](https://ra1ahq.blog/en/archives_month:jun_2024)
- [ May 2024 ✒ 7 ](https://ra1ahq.blog/en/archives_month:may_2024)
- [ April 2024 ✒ 5 ](https://ra1ahq.blog/en/archives_month:apr_2024)
- [ March 2024 ✒ 5 ](https://ra1ahq.blog/en/archives_month:mar_2024)
- [ February 2024 ✒ 5 ](https://ra1ahq.blog/en/archives_month:feb_2024)
- [ January 2024 ✒ 6 ](https://ra1ahq.blog/en/archives_month:jan_2024)
- [ December 2023 ✒ 7 ](https://ra1ahq.blog/en/archives_month:dec_2023)
- [ November 2023 ✒ 4 ](https://ra1ahq.blog/en/archives_month:nov_2023)
- [ October 2023 ✒ 8 ](https://ra1ahq.blog/en/archives_month:oct_2023)
- [ September 2023 ✒ 7 ](https://ra1ahq.blog/en/archives_month:sep_2023)
- [ August 2023 ✒ 4 ](https://ra1ahq.blog/en/archives_month:aug_2023)
- [ July 2023 ✒ 7 ](https://ra1ahq.blog/en/archives_month:jul_2023)
- [ June 2023 ✒ 7 ](https://ra1ahq.blog/en/archives_month:jun_2023)
- [ May 2023 ✒ 5 ](https://ra1ahq.blog/en/archives_month:may_2023)
- [ April 2023 ✒ 6 ](https://ra1ahq.blog/en/archives_month:apr_2023)
- [ March 2023 ✒ 5 ](https://ra1ahq.blog/en/archives_month:mar_2023)
- [ February 2023 ✒ 2 ](https://ra1ahq.blog/en/archives_month:feb_2023)
- [ January 2023 ✒ 5 ](https://ra1ahq.blog/en/archives_month:jan_2023)
- [ December 2022 ✒ 7 ](https://ra1ahq.blog/en/archives_month:dec_2022)
- [ November 2022 ✒ 8 ](https://ra1ahq.blog/en/archives_month:nov_2022)
- [ October 2022 ✒ 6 ](https://ra1ahq.blog/en/archives_month:oct_2022)
- [ September 2022 ✒ 9 ](https://ra1ahq.blog/en/archives_month:sep_2022)
- [ August 2022 ✒ 8 ](https://ra1ahq.blog/en/archives_month:aug_2022)
- [ July 2022 ✒ 4 ](https://ra1ahq.blog/en/archives_month:jul_2022)
- [ June 2022 ✒ 9 ](https://ra1ahq.blog/en/archives_month:jun_2022)
- [ May 2022 ✒ 7 ](https://ra1ahq.blog/en/archives_month:may_2022)
- [ April 2022 ✒ 3 ](https://ra1ahq.blog/en/archives_month:apr_2022)
- [ March 2022 ✒ 4 ](https://ra1ahq.blog/en/archives_month:mar_2022)
- [ February 2022 ✒ 6 ](https://ra1ahq.blog/en/archives_month:feb_2022)
- [ January 2022 ✒ 7 ](https://ra1ahq.blog/en/archives_month:jan_2022)
- [ December 2021 ✒ 7 ](https://ra1ahq.blog/en/archives_month:dec_2021)
- [ November 2021 ✒ 7 ](https://ra1ahq.blog/en/archives_month:nov_2021)
- [ October 2021 ✒ 7 ](https://ra1ahq.blog/en/archives_month:oct_2021)
- [ September 2021 ✒ 10 ](https://ra1ahq.blog/en/archives_month:sep_2021)
- [ August 2021 ✒ 6 ](https://ra1ahq.blog/en/archives_month:aug_2021)
- [ July 2021 ✒ 7 ](https://ra1ahq.blog/en/archives_month:jul_2021)
- [ June 2021 ✒ 7 ](https://ra1ahq.blog/en/archives_month:jun_2021)
- [ May 2021 ✒ 7 ](https://ra1ahq.blog/en/archives_month:may_2021)
- [ April 2021 ✒ 4 ](https://ra1ahq.blog/en/archives_month:apr_2021)
- [ March 2021 ✒ 4 ](https://ra1ahq.blog/en/archives_month:mar_2021)
- [ February 2021 ✒ 3 ](https://ra1ahq.blog/en/archives_month:feb_2021)
- [ January 2021 ✒ 4 ](https://ra1ahq.blog/en/archives_month:jan_2021)
- [ December 2020 ✒ 8 ](https://ra1ahq.blog/en/archives_month:dec_2020)
- [ November 2020 ✒ 2 ](https://ra1ahq.blog/en/archives_month:nov_2020)
- [ October 2020 ✒ 3 ](https://ra1ahq.blog/en/archives_month:oct_2020)
- [ September 2020 ✒ 3 ](https://ra1ahq.blog/en/archives_month:sep_2020)
- [ August 2020 ✒ 5 ](https://ra1ahq.blog/en/archives_month:aug_2020)
- [ July 2020 ✒ 5 ](https://ra1ahq.blog/en/archives_month:jul_2020)
- [ June 2020 ✒ 8 ](https://ra1ahq.blog/en/archives_month:jun_2020)
- [ May 2020 ✒ 10 ](https://ra1ahq.blog/en/archives_month:may_2020)
- [ April 2020 ✒ 4 ](https://ra1ahq.blog/en/archives_month:apr_2020)
- [ March 2020 ✒ 2 ](https://ra1ahq.blog/en/archives_month:mar_2020)
- [ January 2020 ✒ 1 ](https://ra1ahq.blog/en/archives_month:jan_2020)
- [ December 2019 ✒ 2 ](https://ra1ahq.blog/en/archives_month:dec_2019)

## Search

## Weather forecast

[На 14 дней](https://world-weather.ru/pogoda/russia/saint_petersburg/14days/)
[world-weather.ru](https://world-weather.ru/)

---

## Navigation

- Parent: [RA1AHQ](https://ra1ahq.blog/en/index.md)
- Previous: [Launching of Wireshark without sudo and organization of a ring buffer for capture of LAN traffic](https://ra1ahq.blog/en/zapusk-wireshark-bez-sudo-i-organizaciya-kolcevogo-bufera-zakhvata.md)
- Next: [Optimizing Mozilla FireFox Performance - Part 2](https://ra1ahq.blog/en/optimizaciya-proizvoditelnosti-mozilla-firefox-chast-2.md)
