Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Frank Smith <fsmith@hoovers.com>
To: Maciej Soltysiak <solt@dns.toxicfilms.tv>
Cc: Netfilter <netfilter@lists.netfilter.org>
Subject: Re: limit match log question
Date: Wed, 30 Apr 2003 10:39:03 -0500	[thread overview]
Message-ID: <29940000.1051717143@hoovers-59.hoovers.com> (raw)
In-Reply-To: <Pine.LNX.4.51.0304301712450.18203@dns.toxicfilms.tv>

--On Wednesday, April 30, 2003 17:13:50 +0200 Maciej Soltysiak <solt@dns.toxicfilms.tv> wrote:

>> If you are using the limit match to control the number of log entries,
>> is there any way to also show the number of matches?
> Yes,
>
># iptables -L -nv
>
> -v option will show the number of packets that has hit the rule.

Thanks for the reply, but it seems I wasn't clear on my question.  I was
looking for a way to get the number logged, so when the log entry was
written it would contain the number of matches that occurred during the
log limit interval.  If the log limit interval were set to 5 seconds, and
it got 1000 matches in that 5 seconds, the log entry would contain the
number 1000 in it somewhere.
   It seemed to me like a useful extension that would enable you to reduce
log file sizes while still providing data on the frequency of events. Getting
the counters from iptables on the command line is helpful for seeing what's
going on right now, but doesn't help if you want data from some time in the
past.

Frank

--
Frank Smith                                             fsmith@hoovers.com
Systems Administrator                                  Voice: 512-374-4673
Hoover's Online                                          Fax: 512-374-4501


      reply	other threads:[~2003-04-30 15:39 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-04-30 14:52 limit match log question Frank Smith
2003-04-30 15:13 ` Maciej Soltysiak
2003-04-30 15:39   ` Frank Smith [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=29940000.1051717143@hoovers-59.hoovers.com \
    --to=fsmith@hoovers.com \
    --cc=netfilter@lists.netfilter.org \
    --cc=solt@dns.toxicfilms.tv \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox