On OpenBSD, the ipf log is rotated once a day; I let the script run one minute later on the ipf.log.0.gz. So I always only get the logs from the last day.

On a default-configured Debian, however, the /var/log/messages is rotated only so often so the hack with "diff -f | grep ^>" is necessary in order to avoid duplicate lines in analog's input file.

> He does suggest that "It would be good if there was an overview per
> servicetype that got logged". Just passing on suggestions :)
There is. The Blocked Packet Report. I don't know if he means "tcp/udp/icmp" or "ftp/http/domain/etc" but both of them are in the Blocked Packet Report.

The whole concept of fwanalog is to use Analog for creating the reports - if a report type is not in Analog, I can't create it either. (It *could* be possible to play with the Request Report which isn't currently used by creating the right REQOUTPUTALIAS. Perhaps I will look into it.)

Could you invite him to join the mailing list?

No need to, I just added your 3 addresses to the allowed list. Mailman is very flexible.


