Development Lessons of IT Administration

Thursday, May 7, 2009

Wireshark Filters for OpenBSD's PF logs

By accident I found how to create a few Wireshark filters for OpenBSD PF logs.

View by PF Rule Number: pflog.rulenr == xx (where xx is the rule number)
View only Passed Packets: pflog.action == 0
View only Blocked Packets: pflog.action == 1
View by Network Interface: pflog.ifname == "xxxx" (name of the interface in ifconfig)

This should save me some time when going over the logs.
Posted by Unknown at 1:51 PM No comments:
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Blog Archive

  • ►  2016 (2)
    • ►  October (1)
    • ►  August (1)
  • ►  2015 (2)
    • ►  October (1)
    • ►  June (1)
  • ►  2014 (1)
    • ►  March (1)
  • ►  2013 (4)
    • ►  March (3)
    • ►  January (1)
  • ►  2012 (17)
    • ►  November (2)
    • ►  September (2)
    • ►  August (1)
    • ►  July (4)
    • ►  April (1)
    • ►  March (3)
    • ►  January (4)
  • ►  2011 (17)
    • ►  November (1)
    • ►  July (3)
    • ►  June (1)
    • ►  May (1)
    • ►  April (10)
    • ►  January (1)
  • ►  2010 (14)
    • ►  December (2)
    • ►  September (1)
    • ►  August (1)
    • ►  June (4)
    • ►  May (2)
    • ►  February (1)
    • ►  January (3)
  • ▼  2009 (13)
    • ►  October (1)
    • ►  September (1)
    • ►  August (1)
    • ►  July (3)
    • ►  June (1)
    • ▼  May (1)
      • Wireshark Filters for OpenBSD's PF logs
    • ►  April (3)
    • ►  March (1)
    • ►  January (1)
  • ►  2008 (17)
    • ►  December (2)
    • ►  September (2)
    • ►  August (2)
    • ►  July (5)
    • ►  May (6)

About Me

Unknown
View my complete profile
Simple theme. Powered by Blogger.