Allow me one more question
Typical example:
LOCAL0.NOTICE: Feb 3 17:42:13 ipmon[85]: 17:42:12.967581 vr2 @100:3 p 172.16.15.31,2149 -> 74.125.232.18,80 PR tcp len 20 48 -S K-S IN
Host from local network 172.16.0.0 browses google.ru (tcp and target port 80). The packes passed (p after vr2 @100:3). "len" can be understood as length? If so, what's lenght? Is information about "-S K-S IN" not available?