Log Labels?

Petersen, Mark MPetersen at gs1us.org
Wed Mar 11 11:35:03 PDT 2009


I'm trying to find out if it's possible to do IPF like log-tags with pf.
I found an interesting patch here -
that enables this.  It doesn't appear to have made it into pflog though.

Is there a way to use this feature?  I'd much rather be logging a label
and rule #.  I can see if these patches still work with 7 of course.
Has anyone tried this?

Finally - it appears there are only patches for pf, but if I compile
tcpdump with the pf patches, will it work?  What about using mergecap
with this?  If I recompile mergecap/tshark would this work?  I know I
can just try, but no sense reinventing the wheel if someone else spent
some time trying to do the same.


