in reply to iptables log auditing

Thought i would add an update to this thread. I ended up using ipfm and a custom perl script to manipulate. This gives me total up/down bandwidth on a per ip basis. I am still working on a better solution though. Although this is a relatively small network (25 users) reserving ip addresses for auditing does not seem right. I would much rather have the ability to track usage on a per user basis. I am unsure whether this is viable using Linux. Any thoughts to add would be great