startcomment

-----------------------------------------------------------------------
These are the data fields in the packet log structure that can be used 
in the output preprocessor. You can output whitespace by using the tokens 
'sp' 'tab' or 'nl' (no quotes). The data field token names will be replaced
with the data from the log entry. If the entry is empty, nothing will print
for that field. For example, if it is an ICMP packet and you have a token for
dstpt (destination port) nothing will appear. If you have the tokens:

 sp r_dstpt  info sp

You will get the following output:

 " ftp "					- for a tcp/udp log entry 
 						  going to port 21
 " Destination Unreachable/Host Unreachable "	- for an icmp packet with
 						  type=3, code=1
Note that spaces must be explicitly declared.
Any other token will output itself. If you wish to use one of the reserved
token names you can simply break it up into two tokens. In the output all
tokens and replacements are concatenated without any whitespace unless you
specify it with sp or nl. Anything between a 'startcomment' and
'endcomment' (no quotes) will be ignored. (Had I not quoted 'endcomment'
the comment section would have ended there).

  -- structure --	-- token name --	-- replacement text --
  	n/a			sp		the space character(' ')
	n/a			nl		the new line character('\n')
	n/a			tab		the tab character('\t')

	ltype			ltype		iptables or ipchains
	char proto[11]		proto		the protocol
	
	char log[1024]		log		the actual log entry
	char month[4]		month		Jan - Dec
	char day[3]		day		1 - 31
	char time[9]		time		00:00:00
	char msg[50]		msg		log messages
	char in[5]		in		interface
	char out[5]		out		interface
	char mac[46]		mac		mac address
	char srcip[16]		srcip		source ip address
	char r_srcip[255]	r_srcip		resolved source address
	char dstip[16]		dstip		destination ip address
	char r_dstip[255]	r_dstip		resolved destination address
	char iplen[6]		iplen		ip header length
	char tos[5]		tos		hex TOS field
	char sflags[6]		sflags		TOS bits (***++ - DTR!!)
	char prec[5]		prec		hex TOS precedence bits
	char pflags[4]		pflags		Precedence bits (*** - !!!)
	char ttl[4]		ttl		time to live
	char id[6]		id		ip ID
	char frag[145]		frag		fragment data
	char fflags[4]		fflags		IP flags (+** - CDM)
	
ICMP SPECIFIC	
	char type[4]		type		icmp type number
	char code[4]		code		icmp code number
	char info[128]		info		resolved icmp information
	char trigger[260]	trigger		the triggering packet's data
						- netfilter only/Code !8, !0
						
	struct pktlog *recursed	recursed	the resolved information for
						the triggering packet.
						- netfilter only

TCP SPECIFIC	
	char window[6]		window		TCP window
	char res[5]		res		hex TCP reserved bits
	char flags[23]		flags		TCP flags, text (SYN only for
							ipchains)
	char tflags[9]		tflags		TCP flag bits (++***** -
							!!UAPRSF)
	
UDP SPECIFIC
	char ulen[6]		ulen		datagram length
	
TCP/UDP	
	char srcpt[6]		srcpt		source port number
	char r_srcpt[16]	r_srcpt		source port, resolved
	char dstpt[6]		dstpt		destination port number
	char r_dstpt[16]	r_dstpt		destination port, resolved
  
--------------------------------------------------------------------------

I like the look of the one below. - endcomment

time / month - day sp tflags sp proto sp fflags sp msg sp in sp pflags | sflags sp ttl: ttl nl 
sp sp r_srcip sp -> sp r_dstpt ( dstpt info ) nl
sp sp sp sp srcip : srcpt sp -> sp r_dstip : dstpt sp sp nl recursed nl

startcomment This one is a one liner
month sp day sp time sp msg sp proto sp r_srcip : srcpt sp -> sp r_dstpt ( dstpt info ) nl
endcomment

startcomment This one is very verbose
nl LOG sp ENTRY: nl
log
nl CONTEXT sp INFORMATION: nl
tab Time: tab tab month sp day sp time nl
tab Msg: tab tab msg nl
tab In: tab tab in nl
tab Out: tab tab out nl
tab Mac: tab tab mac nl nl
IP sp DATAGRAM sp INFORMATION: nl
tab Source: tab tab srcip tab r_srcip nl
tab Dest.: tab tab dstip tab r_dstip nl
tab IPlen: tab tab iplen nl
tab TOS: tab tab TOS- tos , sp PREC- prec sp -> sp pflags | sflags nl
tab TTL: tab tab ttl nl
tab FRAG: tab tab frag sp -> sp fflags nl nl
ICMP sp SPECIFIC sp DATA: nl
tab Type: tab tab type nl
tab Code: tab tab code nl
tab Info: tab tab info nl
tab Triggering sp Packet: tab trigger nl nl
TCP sp SPECIFIC sp DATA: nl
tab Window: tab tab window nl
tab Reserved sp Bits: tab res nl
tab Flags: tab tab flags sp -> sp tflags nl nl
UDP sp SPECIFIC sp DATA: nl
tab UDP sp Datagram sp length: sp ulen nl nl
TCP/UDP sp SERVICE sp PORTS: nl
tab Source sp Port: tab srcpt ( r_srcpt ) sp -> sp dstpt ( r_dstpt ) nl nl
endcomment

startcomment

The next one can be used with the "decode.php" file in the installation
directory to set up a web-based log decoder.


<H4> Log sp Entry</h4> log <HR>
<TABLE sp BORDER=1><TR><TD><H5> CONTEXT sp INFORMATION: </h5><TD sp COLSPAN=2>Machine sp and sp logging sp rules sp generate sp this sp data</tr>
<TR><TD> Firewall sp Type: <TD> ltype <TD>IPCHAINS sp or sp IPTABLES sp (netfilter)</tr>
<TR><TD> Time: <TD> month sp day sp time <TD> When sp the sp packet sp came sp in</tr>
<TR><TD> Msg: <TD> msg <TD>Log sp message sp (netfilter)<BR>ACTION/chain-rule sp number sp (ipchains)</tr>
<TR><TD> In: <TD> in <TD>Incoming sp interface</tr>
<TR><TD> Out: <TD> out <TD>Outgoing sp interface(netfilter sp only)</tr>
<TR><TD> Mac: <TD> mac <TD>Adapter sp address(netfilter sp only, sp if sp packet sp came sp i n sp on sp an sp ethernet sp adapter)</tr></table><BR>
<TABLE sp BORDER=1><TR><TD><h5>IP sp DATAGRAM sp INFORMATION: </h5><TD sp COLSPAN=2>The sp network sp layer sp data</tr>
<TR><TD> Protocol: <TD sp COLSPAN=2> proto </tr>
<TR><TD> Source: <TD> IP: sp srcip <BR> NAME:<BR> r_srcip <TD>The sp source sp address<BR><A sp HREF=http://real.cotse.com/cgi-bin/dtools2?a= srcip &c=Dig+ipaddress&h=>COTSE sp Lookup</a></tr>
<TR><TD> Destination: <TD> IP: sp dstip <BR> NAME:<BR> r_dstip <TD>The sp destination sp address<BR><A sp HREF=http://real.cotse.com/cgi-bin/dtools2?a= dstip &c=Dig+ipaddress&h=>COTSE sp Lookup</a></tr>
<TR><TD> IPlen: <TD> iplen <TD>The sp IP sp datagram sp length</tr>
<TR><TD> TOS: <TD> TOS(hex)- tos <BR> BITS: sp sflags <TD>Type sp Of sp Service sp fla gs<BR>DELAY sp | sp THROUGHPUT sp | sp RELIABILITY sp | sp Monetary/ECT(ECN) sp | sp Reserved/CE(ECN)</tr>
<TR><TD> PREC: <TD> PREC(hex)- prec <BR> BITS: sp pflags <TD>Precedence sp fla gs</tr>
<TR><TD> TTL: <TD> ttl <TD>Time sp to sp live</tr>
<TR><TD> ID: <TD> id <TD>The sp IP sp ID sp number sp gets sp incremented sp with sp every sp packet</tr>
<TR><TD> FRAG: <TD> BITS: sp fflags <TD>Reserved/Congestion sp | sp Don't sp Fragment sp | sp More sp Fragments</tr></table><BR>
<TABLE sp BORDER=1><TR><TD><h5> proto sp SERVICE sp PORTS: </h5><TD COLSPAN=2></tr>
<TR><TD> Source/Dest. Port: <TD> srcpt ( r_srcpt ) sp -> sp dstpt ( r_dstpt )<TD>Source sp and sp Destination sp Ports<BR><A sp HREF=http://www.isi.edu/in-notes/iana/assignments/port-numbers>IANA</a> </tr></table><BR>
<TABLE sp BORDER=1><TR><TD><H5>TCP sp SPECIFIC sp DATA: </h5><TD sp COLSPAN=2>Transfer sp Control sp Protocol</tr>
<TR><TD> TCP sp Window: <TD> window <TD>TCP sp sliding sp wind ow sp (netfilter sp only)</tr>
<TR><TD> Reserved sp Bits: <TD> res <TD>Netfilter sp only</tr>
<TR><TD> Flags: <TD> tflags <TD>TCP sp flag sp bits(ipchains-SYN sp only)<BR>RES1/CWR sp | sp RES2/ECN-E sp | sp URG sp | sp ACK sp | sp PSH sp | sp RST sp | sp SYN sp | sp FIN</tr></table><BR>
<TABLE sp BORDER=1><TR><TD><H5>UDP sp SPECIFIC sp DATA: </h5><TD>User sp Datagram sp Protocol</tr>
<TR><TD> UDP sp Datagram sp length: <TD> ulen </tr></table><BR>
<TABLE sp BORDER=1><TR><TD><h5>ICMP sp SPECIFIC sp DATA: </h5><TD sp COLSPAN=2>Internet sp Control sp Message sp Protocol</tr>
<TR><TD> Type: <TD> type </tr>
<TR><TD> Code: <TD> code </tr>
<TR><TD> Info: <TD> info <TD>What sp this sp ICMP sp message sp means<BR><A sp HREF=http://www.isi.edu/in-notes/iana/assignments/icmp-parameters>IANA</a></tr>
<TR><TD> Triggering sp Packet: <TD> trigger <TD>Netfilter sp only, sp the sp packet sp that sp caused sp this sp control sp message sp to sp be sp sent.<BR>If sp you sp see sp any sp data sp here sp the sp next sp lo g sp entry sp will sp show sp the sp decoded sp triggering sp packet.</tr></table><BR>
<HR>
recursed
endcomment
