Thank you very much, estabroo! Your suggestion solved my problem
For future googlers:
The log format of ulog with output plugin LOGEMU is as follows (examples):
Sep 17 09:05:34 debianWorkstationMGerdesVM IPT FORWARD packet died: IN=eth0 OUT=eth0 MAC=00:0c:29:f2:f0:bc:00:0c:29:60:81:b3:08:00 SRC=192.168.88.132 DST=212.227.15.167 LEN=60 TOS=00 PREC=0x00 TTL=63 ID=34669 CE DF PROTO=TCP SPT=3425 DPT=25 SEQ=467144633 ACK=0 WINDOW=5840 SYN URGP=0
Sep 17 09:05:35 debianWorkstationMGerdesVM IPT INPUT packet died: IN=eth0 OUT= MAC=00:0c:29:f2:f0:bc:00:0c:29:60:81:b3:08:00 SRC=192.168.88.132 DST=192.168.88.131 LEN=84 TOS=00 PREC=0x00 TTL=64 ID=0 DF PROTO=ICMP TYPE=8 CODE=0 ID=12302 SEQ=1
Sep 17 09:09:52 debianWorkstationMGerdesVM IPT OUTPUT packet died: IN= OUT=eth0 MAC= SRC=192.168.88.131 DST=192.168.88.132 LEN=60 TOS=00 PREC=0x00 TTL=64 ID=31252 DF PROTO=TCP SPT=2208 DPT=100 SEQ=949374304 ACK=0 WINDOW=5840 SYN URGP=0
The MAC adresses, where given, are 14 tupels long. the first 6 are the destination, the second 6 the source, and the last two always 08:00 (at least I never saw anything else.).