/etc/rsyslog.d/arno-iptables-firewall.conf is in arno-iptables-firewall 2.0.1.d-1.
This file is owned by root:root, with mode 0o644.
The actual contents of the file can be viewed below.
1 2 3 4 5 6 7 | # Log firewall messages to /var/log/arno-iptables-firewall (asynchronously),
# and then drop them so that they aren't logged again elsewhere.
if $syslogfacility-text == 'kern' \
and $syslogpriority-text == 'info' \
and $msg contains 'AIF:' then -/var/log/arno-iptables-firewall
& ~
|