I noticed I'm in Blaze's signature >:] Hot.
So am I!
Today afternoon I had to do a ton of walking for a really dumb reason.
See, we have our network sensors. They detect malicious traffic coming from the Internet. A week ago, they moved one of the sensors into a new building, and since then we haven't been seeing any traffic from it. This is unusual, because we generally see SQL Slammer at least 30 times/minute.
So we walked over to the building, got let into the server room, and checked the Switch's configuration. We figured it wasn't set to SPAN properly. That checked out.
Next, we thought it was the port itself. We plugged in a laptop, loaded ethereal, and saw about 5000packets/second. So that worked fine.
So maybe it was the cable! We followed it down to the server, plugged in the laptop, and bam, 5000packets/second. Hmm!
So we go to reinstall the software on the server. We hit reboot, and discover that the CMOS battery was dead. What that means is that, when they moved it to the new building, the date got reset to 2001.
As it turns out, the sensor was working fine. It was sending out the data to our console fine. However, since the data was dated 2001, it was putting it all waaaaaaay the hell back in the database, where we'd never see it.
So yay, it's working now! :-)