update :
a tcpdump give alot of mongo 27017 traffic :
09:32:55.359760 IP 10.4.1.215.55466 > 10.4.1.214.12900: Flags [P.], seq 1504:1973, ack 2131, win 1444, options [nop,nop,TS val 2130363701 ecr 1646958687], length 469
09:32:55.360077 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 28806:28962, ack 142317, win 4705, options [nop,nop,TS val 2915888533 ecr 3761703252], length 156
09:32:55.360302 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 142317:142482, ack 28962, win 1452, options [nop,nop,TS val 3761703286 ecr 2915888533], length 165
09:32:55.360327 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [.], ack 142482, win 4705, options [nop,nop,TS val 2915888533 ecr 3761703286], length 0
09:32:55.360628 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 28962:29119, ack 142482, win 4705, options [nop,nop,TS val 2915888533 ecr 3761703286], length 157
09:32:55.360941 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 142482:143383, ack 29119, win 1452, options [nop,nop,TS val 3761703286 ecr 2915888533], length 901
09:32:55.361164 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 29119:29276, ack 143383, win 4705, options [nop,nop,TS val 2915888534 ecr 3761703286], length 157
09:32:55.361485 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 143383:144284, ack 29276, win 1452, options [nop,nop,TS val 3761703287 ecr 2915888534], length 901
09:32:55.361699 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 29276:29433, ack 144284, win 4705, options [nop,nop,TS val 2915888534 ecr 3761703287], length 157
09:32:55.362019 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 144284:145185, ack 29433, win 1452, options [nop,nop,TS val 3761703287 ecr 2915888534], length 901
09:32:55.362231 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 29433:29590, ack 145185, win 4705, options [nop,nop,TS val 2915888535 ecr 3761703287], length 157
09:32:55.362547 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 145185:146086, ack 29590, win 1452, options [nop,nop,TS val 3761703287 ecr 2915888535], length 901
09:32:55.362755 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 29590:29747, ack 146086, win 4705, options [nop,nop,TS val 2915888535 ecr 3761703287], length 157
09:32:55.363075 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 146086:146987, ack 29747, win 1452, options [nop,nop,TS val 3761703287 ecr 2915888535], length 901
09:32:55.363283 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 29747:29904, ack 146987, win 4705, options [nop,nop,TS val 2915888536 ecr 3761703287], length 157
09:32:55.363604 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 146987:147888, ack 29904, win 1452, options [nop,nop,TS val 3761703287 ecr 2915888536], length 901
09:32:55.363819 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 29904:30061, ack 147888, win 4705, options [nop,nop,TS val 2915888536 ecr 3761703287], length 157
09:32:55.364048 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 147888:148789, ack 30061, win 1452, options [nop,nop,TS val 3761703287 ecr 2915888536], length 901
09:32:55.364258 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 30061:30218, ack 148789, win 4705, options [nop,nop,TS val 2915888537 ecr 3761703287], length 157
09:32:55.364518 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 148789:149690, ack 30218, win 1452, options [nop,nop,TS val 3761703287 ecr 2915888537], length 901
09:32:55.364725 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 30218:30375, ack 149690, win 4705, options [nop,nop,TS val 2915888537 ecr 3761703287], length 157
09:32:55.364971 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 149690:150591, ack 30375, win 1452, options [nop,nop,TS val 3761703287 ecr 2915888537], length 901
09:32:55.365180 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 30375:30532, ack 150591, win 4705, options [nop,nop,TS val 2915888538 ecr 3761703287], length 157
09:32:55.365429 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 150591:151492, ack 30532, win 1452, options [nop,nop,TS val 3761703288 ecr 2915888538], length 901
09:32:55.365636 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 30532:30628, ack 151492, win 4705, options [nop,nop,TS val 2915888538 ecr 3761703288], length 96
09:32:55.365872 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 151492:152094, ack 30628, win 1452, options [nop,nop,TS val 3761703288 ecr 2915888538], length 602
09:32:55.366093 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 30628:30785, ack 152094, win 4705, options [nop,nop,TS val 2915888539 ecr 3761703288], length 157
09:32:55.366357 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 152094:152995, ack 30785, win 1452, options [nop,nop,TS val 3761703288 ecr 2915888539], length 901
09:32:55.366569 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 30785:30942, ack 152995, win 4705, options [nop,nop,TS val 2915888539 ecr 3761703288], length 157
09:32:55.366814 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 152995:153896, ack 30942, win 1452, options [nop,nop,TS val 3761703288 ecr 2915888539], length 901
09:32:55.367091 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 30942:31099, ack 153896, win 4705, options [nop,nop,TS val 2915888540 ecr 3761703288], length 157
09:32:55.367339 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 153896:154797, ack 31099, win 1452, options [nop,nop,TS val 3761703288 ecr 2915888540], length 901
09:32:55.367549 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 31099:31256, ack 154797, win 4705, options [nop,nop,TS val 2915888540 ecr 3761703288], length 157
09:32:55.367792 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 154797:155698, ack 31256, win 1452, options [nop,nop,TS val 3761703288 ecr 2915888540], length 901
09:32:55.368135 IP 10.4.1.214.12900 > 10.4.1.215.55466: Flags [P.], seq 2131:2595, ack 1973, win 1452, options [nop,nop,TS val 1646960022 ecr 2130363701], length 464
and then
09:32:56.110683 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 31256:31407, ack 155698, win 4705, options [nop,nop,TS val 2915889283 ecr 3761703288], length 151
09:32:56.111048 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 155698:156022, ack 31407, win 1452, options [nop,nop,TS val 3761703474 ecr 2915889283], length 324
09:32:56.111065 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [.], ack 156022, win 4705, options [nop,nop,TS val 2915889284 ecr 3761703474], length 0
09:32:56.111208 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 31407:31744, ack 156022, win 4705, options [nop,nop,TS val 2915889284 ecr 3761703474], length 337
09:32:56.111477 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 156022:156097, ack 31744, win 1452, options [nop,nop,TS val 3761703474 ecr 2915889284], length 75
09:32:56.111559 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 31744:31889, ack 156097, win 4705, options [nop,nop,TS val 2915889284 ecr 3761703474], length 145
09:32:56.111795 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 156097:156157, ack 31889, win 1452, options [nop,nop,TS val 3761703474 ecr 2915889284], length 60
09:32:56.111901 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 31889:32024, ack 156157, win 4705, options [nop,nop,TS val 2915889285 ecr 3761703474], length 135
09:32:56.112121 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 156157:156478, ack 32024, win 1452, options [nop,nop,TS val 3761703474 ecr 2915889285], length 321
09:32:56.112208 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 32024:32168, ack 156478, win 4705, options [nop,nop,TS val 2915889285 ecr 3761703474], length 144
09:32:56.112471 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 156478:156538, ack 32168, win 1452, options [nop,nop,TS val 3761703474 ecr 2915889285], length 60
09:32:56.114507 IP 10.4.1.214.40840 > 10.4.1.57.27017: Flags [P.], seq 32168:32350, ack 156538, win 4705, options [nop,nop,TS val 2915889287 ecr 3761703474], length 182
09:32:56.114810 IP 10.4.1.57.27017 > 10.4.1.214.40840: Flags [P.], seq 156538:156665, ack 32350, win 1452, options [nop,nop,TS val 3761703475 ecr 2915889287], length 127
and repeat
so, maybe it’s linked to mongodb? but why?
anyway thanx, jan for taking your time reading this post :
Keep up, the good work at graylog’s
cheers