First of all ;
Sample that a part of log file;
2014.11.20-07:56:32 <192.168.0.254>: firewall,info port80 forward: in:1-LAN out:2-WAN METRO, src-mac 000, proto TCP (ACK), 192.168.0.150:53359->83.66.162.26:80, NAT (192.168.0.150:53359->195.175.76.58:53359)->83.66.162.26:80, len 40
2014.11.20-07:56:32 <192.168.0.254>: firewall,info port80 forward: in:1-LAN out:2-WAN METRO, src-mac 000, proto TCP (ACK), 192.168.0.150:53359->83.66.162.26:80, NAT (192.168.0.150:53359->195.175.76.58:53359)->83.66.162.26:80, len 40
2014.11.20-07:56:32 <192.168.0.254>: firewall,info port80 forward: in:1-LAN out:2-WAN METRO, src-mac 000, proto TCP (ACK), 192.168.0.150:52371->83.66.162.26:80, NAT (192.168.0.150:52371->195.175.76.58:52371)->83.66.162.26:80, len 40
2014.11.20-07:56:32 <192.168.0.254>: firewall,info port80 forward: in:1-LAN out:2-WAN METRO, src-mac 000, proto TCP (ACK), 192.168.0.150:52371->83.66.162.26:80, NAT (192.168.0.150:52371->195.175.76.58:52371)->83.66.162.26:80, len 40
2014.11.20-07:56:33 <192.168.0.254>: firewall,info port80 forward: in:1-LAN out:2-WAN METRO, src-mac 000, proto TCP (ACK), 192.168.0.150:52371->83.66.162.26:80, NAT (192.168.0.150:52371->195.175.76.58:52371)->83.66.162.26:80, len 52
2014.11.20-07:56:33 <192.168.0.254>: firewall,info port80 forward: in:1-LAN out:2-WAN METRO, src-mac 000, proto TCP (ACK), 192.168.0.150:52371->83.66.162.26:80, NAT (192.168.0.150:52371->195.175.76.58:52371)->83.66.162.26:80, len 52
Exactly it says;
2014.11.20-07:56:32 TCP (ACK), 192.168.0.150:53359->83.66.162.26:80,
2014.11.20-07:56:32 TCP (ACK), 192.168.0.150:53359->83.66.162.26:80,
2014.11.20-07:56:32 TCP (ACK), 192.168.0.150:52371->83.66.162.26:80,
2014.11.20-07:56:32 TCP (ACK), 192.168.0.150:52371->83.66.162.26:80,
2014.11.20-07:56:33 TCP (ACK), 192.168.0.150:52371->83.66.162.26:80,
2014.11.20-07:56:33 TCP (ACK), 192.168.0.150:52371->83.66.162.26:80,
2014.11.20-07:56:33 TCP (ACK,FIN), 192.168.0.153:2924->46.228.164.13:80,
2014.11.20-07:56:33 TCP (ACK,FIN), 192.168.0.153:2924->46.228.164.13:80,
2014.11.20-07:56:33 TCP (ACK), 192.168.0.150:52371->83.66.162.26:80,
2014.11.20-07:56:33 TCP (ACK), 192.168.0.150:52371->83.66.162.26:80,
Wish I could find solution;
i realize that i can not change log format however if i could minimize, couse file size=30Mb per hour…
same src address to same dst address are being showed above,
192.168.0.150:52371->83.66.162.26:80,
How can i filter same (src) to same (dst : port) just one line per a minute
any script, filter rule or solution