# how to measure size of data that transfer in connection?

**URL:** <https://community.zeek.org/t/how-to-measure-size-of-data-that-transfer-in-connection/1443>\
**Category:** Zeek\
**Created:** [November 8, 2008, 6:51pm UTC](https://community.zeek.org/t/how-to-measure-size-of-data-that-transfer-in-connection/1443 "2008-11-08T18:51:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![hossein\_talebi](https://avatars.discourse-cdn.com/v4/letter/h/f17d59/32.png) [@hossein\_talebi](https://community.zeek.org/u/hossein_talebi)\
**Post date:** [November 8, 2008, 6:51pm UTC](https://community.zeek.org/t/how-to-measure-size-of-data-that-transfer-in-connection/1443/1 "2008-11-08T18:51:29Z")

</div>

Hi

i want measure size of data thet transfer in per side(how many recieve and how many send)

I have downloaded one file with size:almost 4MB  
and capture its with tcpdump(only with filtering on tcp header and on my IP )  
and sum of received data in connections almost is:4MB (this sum have been measured in Bro via field of endpoint size in connection)  
then i filter same output of tcpdump only for tcpflags(SYN,SYN-ACK,FIN) and save with pcap format  
and sum of received data in connections almost is:1MB

i don’t know reason of this repugnance  
i need measure size of data that transfer in per side of connection realy while i have filter network traffic only  
for SYN,SYN-ACK,FIN packet header

how to solve this problem?

please help me  
thanks

---

<div class="post-metadata">

**Author:** ![hossein\_talebi](https://avatars.discourse-cdn.com/v4/letter/h/f17d59/32.png) [@hossein\_talebi](https://community.zeek.org/u/hossein_talebi)\
**Post date:** [November 8, 2008, 8:37pm UTC](https://community.zeek.org/t/how-to-measure-size-of-data-that-transfer-in-connection/1443/2 "2008-11-08T20:37:28Z")

</div>

Hi  
my problem is not filtering but my problem is obtain accurate size of transfer byte  
i have checked these policies and apply very much and understand them completly  
but apply conn policy on 2 tcpdump file(that one include all of packet headers and other include only SYN,SYN\_ACK,FIN packet headers) have different results  
why???  
thanks

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:38pm UTC](https://community.zeek.org/t/how-to-measure-size-of-data-that-transfer-in-connection/1443/3 "2022-05-06T15:38:46Z")

</div>


