in reply to iptables log auditing

The iptables has a clear (or zero) counters command.

Have a good read of the iptables manual which will give you command line options (including one which reports in numerical format that you will find easier for parsing).

Possibly one approach would be to run a daily cron job script. That script would query iptables for the current counters, and grep for the counters you want. It may then immediately call iptables again with the zero counters command.

There are, of course, hundreds of other approaches but that would be one way of approaching it.

(I'm assuming you know how to configure iptables and set up firewall rules/chains.. if not then you really are out of your depth and your time is best spent googling more information on iptables)