Dec 10 05:12:47 sv1 kernel: IN=eth0 OUT= MAC=ID SRC=someip DST=server.ip LEN=40 TOS=0x00 PREC=0x00 TTL=106 ID=256 PROTO=TCP SPT=6000 DPT=1433 WINDOW=16384 RES=0x00 SYN URGP=0
Dec 10 05:12:59 sv1 kernel: IN=eth0 OUT= MAC=ID SRC=someip DST=server.ip LEN=40 TOS=0x00 PREC=0x00 TTL=54 ID=0 DF PROTO=TCP SPT=37608 DPT=80 WINDOW=0 RES=0x00 RST URGP=0
Dec 10 05:12:59 sv1 kernel: IN=eth0 OUT= MAC=ID SRC=someip DST=server.ip LEN=40 TOS=0x00 PREC=0x00 TTL=54 ID=0 DF PROTO=TCP SPT=37608 DPT=80 WINDOW=0 RES=0x00 RST URGP=0
Dec 10 05:12:59 sv1 kernel: IN=eth0 OUT= MAC=ID SRC=someip DST=server.ip LEN=40 TOS=0x00 PREC=0x00 TTL=54 ID=0 DF PROTO=TCP SPT=37608 DPT=80 WINDOW=0 RES=0x00 RST URGP=0
Dec 10 05:12:59 sv1 kernel: IN=eth0 OUT= MAC=ID SRC=someip DST=server.ip LEN=40 TOS=0x00 PREC=0x00 TTL=54 ID=0 DF PROTO=TCP SPT=37608 DPT=80 WINDOW=0 RES=0x00 RST URGP=0
Dec 10 05:12:59 sv1 kernel: IN=eth0 OUT= MAC=ID SRC=someip DST=server.ip LEN=40 TOS=0x00 PREC=0x00 TTL=54 ID=0 DF PROTO=TCP SPT=37608 DPT=80 WINDOW=0 RES=0x00 RST URGP=0
Dec 10 05:12:59 sv1 kernel: IN=eth0 OUT= MAC=ID SRC=someip DST=server.ip LEN=40 TOS=0x00 PREC=0x00 TTL=54 ID=0 DF PROTO=TCP SPT=37608 DPT=80 WINDOW=0 RES=0x00 RST URGP=0
Dec 10 05:15:05 sv1 kernel: IN=eth0 OUT= MAC=ID SRC=someip DST=server.ip LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=0 DF PROTO=TCP SPT=37827 DPT=80 WINDOW=0 RES=0x00 RST URGP=0
Dec 10 05:15:05 sv1 kernel: IN=eth0 OUT= MAC=ID SRC=someip DST=server.ip LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=0 DF PROTO=TCP SPT=37827 DPT=80 WINDOW=0 RES=0x00 RST URGP=0
Dec 10 05:15:05 sv1 kernel: IN=eth0 OUT= MAC=ID SRC=someip DST=server.ip LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=0 DF PROTO=TCP SPT=37827 DPT=80 WINDOW=0 RES=0x00 RST URGP=0
The rule you gave to log output port, I used the same rule to log input port.