I'd like to monitor an external IP for any connections to my firewall and log them - nothing else.
Without turning on all logging, what's the correct way to set up a firewall rule so that I can log the connections from the IP without interfering with any other rule e.g. if it would normally be blocked keeping it blocked, if it's allowed/forwarded then leave it alone.