• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

I would like to see my logs a bit more… clear and understandable

Scheduled Pinned Locked Moved General pfSense Questions
3 Posts 3 Posters 932 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    czar666
    last edited by Aug 3, 2016, 3:26 PM

    Hi,
    My firewall logs are sent to a remote syslog server. They are coming in so everything is fine. Now I would like to see them in a more comprehensive manner.
    In the pfSense book they are talking about # clog /var/log/filter.log | filterparser.php. And that helped. But that's on the pfSense box, not on my syslog server. I added a screenshot to this post. Btw, if someone has other options to check logs, please share. I read something about Splunk, Opennms and Nagios but I admit I still have to check those options. Oh and I just want to add that it's for SOHO. So nothing too fancy or no overkill. I just want to experiment and learn. Thanks in advance.

    pfsense1.PNG
    pfsense1.PNG_thumb

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Aug 3, 2016, 7:48 PM

      You'll need to have something parse them on the syslog server in that case. There isn't a supported way to send the formatted log entries over, just the raw data. It's easy to parse since it's CSV style data and we have the format documented: https://doc.pfsense.org/index.php/Filter_Log_Format_for_pfSense_2.2

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • A
        AR15USR
        last edited by Aug 3, 2016, 9:10 PM

        There is a pre-made pfELK virtual machine you could try:

        https://www.reddit.com/r/PFSENSE/comments/4dymci/i_made_a_simple_bare_bones_simple_elk_vm_for/


        2.6.0-RELEASE

        1 Reply Last reply Reply Quote 0
        3 out of 3
        • First post
          3/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received