then counter, C-O-U-N-T-E-R, counter my logs. So you're just finding a match from a source address, and of course it doesn't have to be from a single address. You could open it up to an entire subnet or to an entire whatever. But you can then counter my log, or actually counter space name space my logs, and that sends the statistics of those matches into my logs. You can retrieve the stats, again with nfacct list, that shows you the data. And you can reset them or delete them with either delete or the keyword zero. So if you want to reset, you can do sudo user sbin nfacct zero my logs, and that'll zero it out. So if you want to see how much traffic you're getting from a specific block of IP addresses overnight, you could do that, come in the morning, see what you got, zero them out, see how it performs during the day, or whatever your use case. It's not well documented. If you go to netfilter.org, you get a little bit of information, but really the place you're going to really need to (53/55)
You are viewing a single comment's thread from: