Tracing an unexpected rise in hosting bandwidth

An unexpected bandwidth increase should be traced to the service and content producing it. Large downloads, bot traffic, mail activity and a compromised application require different remedies.

Gather the details you will need

Record the affected period and compare it with a normal baseline. Check the plan’s own bandwidth definition because a panel chart does not necessarily include every type of network traffic.

01 Trace an unexpected rise in hosting bandwidth

  1. Open Bandwidth and compare the available time ranges and protocol breakdowns. Note when the rise began and which service contributes most.
  2. For web traffic, inspect Raw Access or analytics for frequently downloaded large files, repeated endpoints and unusual request volume.
  3. Review recent legitimate changes such as publishing video files, releasing a downloadable archive or starting a marketing campaign.
  4. If traffic is unwanted, apply a narrow correction such as removing an accidentally public backup, fixing a loop or using an appropriate security rule. Preserve evidence before cleaning suspected compromise.
  5. Monitor the same period and protocol after the change. Contact support before the allocation is exhausted if normal demand requires more capacity.

Confirm the expected result

The chosen action should reduce the identified traffic source without preventing legitimate visitors or mail delivery. Keep evidence that explains the rise rather than only a screenshot of the total.

If the problem continues

Metrics may update on a schedule and can differ from CDN figures because cached requests do not all reach the server. A higher counter alone does not prove an attack. If the source remains unclear, provide support the period, protocol and representative log entries.

Will compressing a file stop repeated downloads?

Compression can reduce bytes for suitable content, but it does not address an abusive requester, exposed private file or application loop. Correct the actual source as well as improving delivery efficiency.

Sources and further reading

  • 0 Users Found This Useful
  • cpanel-whm, performance
Was this answer helpful?

Related Articles

Finding the error behind a cPanel website’s 500 response

A 500 response indicates a server-side failure, but the browser often hides the useful detail....

Downloading raw access logs for an incident investigation

Raw access logs provide request-level evidence for investigating missing pages, suspicious...

Reading CPU and concurrent connection fault information

On services using CloudLinux, cPanel may expose resource usage and fault information for the...

Using Visitors reports to diagnose repeated missing-file requests

The Visitors report helps locate recent requests for missing resources. Repeated 404 responses...