Skip to content

My host says I used 10TB but my monitoring says 2TB

General Discussion by pdxltd 5 replies 405 views
#1

My host says I used 10TB but my monitoring says 2TB Grabs popcorn Following

#2

It has been observed that measurement methodologies can be leveraged to produce divergent outcomes within our partner ecosystem. A value-added redistribution approach has been implemented by certain entities wherein synergy is achieved through the aggregation of upstream telemetry. It is recommended that the switch port metrics be examined, as these are often utilized to generate billing events that do not align with application-layer observations. Additional synergy may be discovered in the scrubbing infrastructure, where mitigation traffic is leveraged and subsequently counted against contractual commitments.

#3

Can you believe this I mean really ten terabytes thats just crazy my whole server cant even hold that much data so how could I use it all I dont get it at all this host is scamming everyone I bet they just make up numbers

#4

The discrepancy is almost certainly between switch port accounting and application-visible traffic. Your host measures at the border router, likely via sFlow or IPFIX from their upstream transit. This captures all packets delivered to your MAC address, including broadcast, multicast, and any traffic filtered before reaching your VM.

More critically, if your host operates inline DDoS mitigation—scrubbing centers with GRE or MPLS backhaul to your hypervisor—the traffic arrives at the switch port, is counted for billing, and is then dropped by the mitigation layer. The 8TB difference suggests you were the target of a volumetric attack, likely UDP reflection, that never reached your application stack. Check if your host publishes a communities document; some providers mark scrubbed traffic with a BGP community that may, in some partner ecosystems, be excluded from billing. Most do not.

iBGP, eBGP, don't care, just peer
#5

We have seen similar confusion in our operations. The gap between what a user observes and what the network records can be substantial when mitigation services are involved. We generally recommend that customers request flow-level breakdowns from their provider to understand the composition of that traffic.

If the host cannot or will not provide this, that is itself useful information. We have found that transparency at the port level builds better long-term relationships than raw volume metrics.

Sam

#6

10TB on a single server sounds high

if it ain't broke, rust it

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft