On Mon, Mar 27, 2006 at 11:52:59AM +0200, Luca Losio wrote:

> is there a way to force pf just to log the header and not the whole
> packet? I'm doing a sniffer and I can't log alle the packets but I
> want at least the headers....

That would be the pcap(3) snaplen, as set with -s with tcpdump(8) and
pflogd(8), for instance.

A default of 96 bytes is sufficient for IP and most protocol headers.

Daniel

Reply via email to