Hello!
I’ve set some custom firewall rules to log specific activity (like remote Magic packets, and remote desktop connections) - I have added custom prefixes for these events to make them easier to find in the exported log file, andto simply visually see when scrolling through the recent logs.
What I would prefere instead is to have all these events to be stored in the separate file on the built-in or USB memory stick that’s plugged in the router. Is that possible to filter out these events with specific prefixes and store them separately, so all these events are in a single log file?
Not directly. The only idea which comes to my mind is to use a scheduler to run /log print follow-only file=your-log-file-name topics~“firewall” message ~“your-key-value” on each startup (or rather periodically e.g. every hour for 1h1m with a distinct file name so that you could implement some “keep only newest N files” management and not lose a single message (at worst it would be in two files if it comes during the overlapping minute).
add new action and select type to disk type name what name that you want to specific your event & option that you want
2. create new rule for your event and select your action that your create