once tcpflow is installed monitor one or several ports for activity. specially if you know you are serving telnet, ssh, ftp, http (80,81,8080,etc), afp, timbuktu, smb,mail, etc.
That way you can actually see the actuall incoming/outgoing requests...
That's just one more suggestion...