*.* /var/log/messages |
/etc/syslogd.conf |
tcpdump allows you to see what packets are being transfered, and their NFS filenames.
tcpdump -i eth0 -s 500 host box |
Your output from syslog should resemble:
Jul 24 21:37:00 bookcase dhcpd: DHCPDISCOVER from 00:80:64:10:1d:1c via eth0 Jul 24 21:37:00 bookcase dhcpd: DHCPOFFER on 192.168.1.52 to 00:80:64:10:1d:1c via eth0 Jul 24 21:37:04 bookcase dhcpd: DHCPREQUEST for 192.168.1.52 from 00:80:64:10:1d:1c via eth0 Jul 24 21:37:04 bookcase dhcpd: DHCPACK on 192.168.1.52 to 00:80:64:10:1d:1c via eth0 Jul 24 21:37:04 bookcase tftpd[5003]: tftpd: trying to get file: /exports/T1500/tftpboot/vmlinux Jul 24 21:37:24 bookcase mountd[4853]: authenticated mount request from box:600 |
Your tcpdump output should look like (when idle):
17:31:41.450000 box.8022008 > bookcase.nfs: 116 lookup fh Unknown/1 "initctl" 17:31:41.450000 bookcase.nfs > box.8022008: reply ok 128 lookup fh Unknown/1 |
12:04:38.506153 box.2049 > bookcase.house.tftp: 39 RRQ "/exports/T1500/tftpboot/vmlinux" 12:04:38.556153 bookcase.house.1199 > box.2049: udp 516 12:04:38.556153 box.2049 > bookcase.house.1199: udp 4 12:04:38.556153 bookcase.house.196610 > box.nfs: 516 null 12:04:38.556153 box.2049 > bookcase.house.1199: udp 4 12:04:38.556153 bookcase.house.196611 > box.nfs: 516 null 12:04:38.556153 box.2049 > bookcase.house.1199: udp 4 12:04:38.556153 bookcase.house.196612 > box.nfs: 516 null 12:04:38.556153 box.2049 > bookcase.house.1199: udp 4 12:04:38.566153 bookcase.house.196613 > box.nfs: 516 null 12:04:38.566153 box.2049 > bookcase.house.1199: udp 4 12:04:38.566153 bookcase.house.196614 > box.nfs: 516 null 12:04:38.566153 box.2049 > bookcase.house.1199: udp 4 12:04:38.566153 bookcase.house.196615 > box.nfs: 516 null |