On Fri, 10 Mar 2006, Jozsef Kadlecsik wrote: > However, you can use ULOG as a target and log the packets by it. Feeding > mySQL/Postgres by ulogd is easy and then you can create such accounting > info as you wish. Oops, I believe I'm lying here - as far as I know currently you cannot *trigger* to log the connection packet and byte counters when a conntrack entry is destroyed. If that piece would be there then in some way we would produce better data that netflow. Best regards, Jozsef - E-mail : kadlec@xxxxxxxxxxxxxxxxx, kadlec@xxxxxxxxxxxxxxx PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt Address : KFKI Research Institute for Particle and Nuclear Physics H-1525 Budapest 114, POB. 49, Hungary