It's just the BPF language that tcpdump and others use.

I would use 'not' instead of '!', e.g. "dst net mask and not net mask"

Also, isn't a valid netmask. Do you mean ?


> [root at enterprise u01]# ramon -M Matrix -n -L0 -r /u01/argus.log - dst net
> mask and ! net mask |
> wc -l
>     341

