Suggestion for ROS

Hi

I use a cisco feature that syslogs all tcp (and udp) session.
So once a session finishes it prints out a log entry. time src ip port dst ip port amount of data and reason for ending ..

Would be nice if ROS could do the same thing.

I was thinking of using ip filter to log syn and fin packets I could in there work it out from there but …

It can do that already in various ways, including firewall log entries and netflow.