Wed Nov 20, 2013 10:22 am
Lol, nice screen.
While this option doesn't explicitly exist, you can do it a couple ways that I can think of.
The thing to keep in mind is that often a filter rule doesn't just match one packet but who knows how many, and you need a way to make sure your script is only being run once and not many times within a few seconds.
1. Create a filter rule that logs a matching packet with a unique prefix. Have a scheduled script check for new log entries every X seconds that contain this prefix. Store the date/time stamp in the comment of the schedule as a way to check that this is a new log entry. If a new log entry is found, the script is run. The interval that you set on the schedule would determine how often the script could possibly be run.
2. Basically the same as above except the filter rule would create an address list entry with a timeout of X seconds. The scheduled script would check for this address list entry and run the script.
These are more like workarounds, but depending on what you're trying to do they could probably be tweaked.