We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
nft log level audit writes the messages into the audit buffer for reading with ausearch.
nft log level audit
ausearch
I want to use it instead of journalctl, but it is very limited. Only shows saddr,daddr and proto:
journalctl
saddr
daddr
proto
ausearch -i -m netfilter_pkt type=NETFILTER_PKT msg=audit(06/20/2024 15:49:52.819:576) : mark=0x0 saddr=<ip> daddr=<ip> proto=tcp ---- type=NETFILTER_PKT msg=audit(06/20/2024 15:49:56.452:577) : mark=0x0 saddr=<ip> daddr=<ip> proto=tcp ...
dpt and spt is needed. For the output packets the sid and gid is needed.
dpt
spt
I can't believe I'm the only one who has this need. No one else has reported it?
The text was updated successfully, but these errors were encountered:
No one else has reported it?
I don't believe so, but I could be wrong. If you are interested in this new functionality, patches are always welcome upstream.
Sorry, something went wrong.
No branches or pull requests
nft log level audit
writes the messages into the audit buffer for reading withausearch
.I want to use it instead of
journalctl
, but it is very limited. Only showssaddr
,daddr
andproto
:dpt
andspt
is needed.For the output packets the sid and gid is needed.
I can't believe I'm the only one who has this need. No one else has reported it?
The text was updated successfully, but these errors were encountered: