Originally Posted by SaintDanBert
...but run-log-view batches are good too.
For that, you can use packet counters, and no tool is necessary. Bit primitive though, depending on how your firewall ruleset is structured, and okcomputer44's suggestion is probably better, unless you intend to leave monitoring in place, long term. Then, the low overhead of packet counting might be valuable