Actually, you can setup something similar in 5.X. I do the following in 5.1
(and have used this method in 4.X as well):
IPF rules:
block in log level local3.info quick from any to any head 01
block out log level local4.info quick from any to any head 02
syslog:
# This takes only syslog messages that come from the ipmon program. The '='
# ensures that only the specified level is sent to each log file.
!ipmon
local3.=info /var/log/ipf/in.log
local4.=info /var/log/ipf/out.log
newsyslog:
/var/log/ipf/in.log 0640 20 100 * Z
/var/log/ipf/out.log 0640 20 100 * Z
Paul
Well. You learn something new every day.
Thanks!