probe::netfilter.ip.local_in — Called on an incoming IP packet addressed to the local computer
netfilter.ip.local_in
ack
TCP ACK flag (if protocol is TCP; ipv4 only)
nf_drop
Constant used to signify a 'drop' verdict
urg
TCP URG flag (if protocol is TCP; ipv4 only)
nf_queue
Constant used to signify a 'queue' verdict
length
The length of the packet buffer contents, in bytes
nf_repeat
Constant used to signify a 'repeat' verdict
daddr
A string representing the destination IP address
saddr
A string representing the source IP address
outdev
Address of net_device representing output device, 0 if unknown
indev_name
Name of network device packet was received on (if known)
indev
Address of net_device representing input device, 0 if unknown
nf_stop
Constant used to signify a 'stop' verdict
protocol
Packet protocol from driver (ipv4 only)
fin
TCP FIN flag (if protocol is TCP; ipv4 only)
outdev_name
Name of network device packet will be routed to (if known)
dport
TCP or UDP destination port (ipv4 only)
sport
TCP or UDP source port (ipv4 only)
rst
TCP RST flag (if protocol is TCP; ipv4 only)
psh
TCP PSH flag (if protocol is TCP; ipv4 only)
ipproto_tcp
Constant used to signify that the packet protocol is TCP
syn
TCP SYN flag (if protocol is TCP; ipv4 only)
nf_stolen
Constant used to signify a 'stolen' verdict
iphdr
Address of IP header
family
IP address family
ipproto_udp
Constant used to signify that the packet protocol is UDP
data_str
A string representing the packet buffer contents
data_hex
A hexadecimal string representing the packet buffer contents
pf
Protocol family -- either “ipv4” or “ipv6”
nf_accept
Constant used to signify an 'accept' verdict