PFTop Rules filter syntax
I know how to use the syntax just fine for pftop default view from the UI in PFSense. But when I change the view to PFTop rules, the filter expression window remains. It does not matter what filter I place, it does not work. Is there a special syntax to filter on rules while in PFTop rules view ? I have tried proto, src, rule number, interface, etc and nothing has any effect on the 335 rules shows to me in the window below
@Orion2030 Please show sample filter
proto tcp and src 192.168.0.123work fine for me on 2.4.5
@viktor_g that syntax works fine for the default view. However, it has no effect in the rule view. Also, rnr rulenumber also did not work for me. I tried this both in the UI and in the CLI way with not success.
@Orion2030 Correct, it works only for states, see https://www.freebsd.org/cgi/man.cgi?query=pftop&apropos=0&sektion=0&manpath=FreeBSD+12.1-RELEASE+and+Ports&arch=default&format=html:
The expression filter selects which states will be displayed. It is based
on the tcpdump filtering language. The following is based on the tcpdump
manual page, modified for state filtering.
@viktor_g thank you for confirming this. By your statement and what I see, then there probably should not be a filter text box input when selecting "View:rule" since it does not apply. ... (?) makes it a bit confusing...