sending zeek logs via syslog or filebeat
-
anyone have any luck getting seek logs to send through syslog or a good reliable walkthrough for getting filbert onto pfsense?
I haven't had much luck, any suggestions would be appreciated
-
@darrell-miller Have you figured it out yet? I am in this same crusade
-
If anyone else is trying to do that, use syslog-ng, it is a package that can be added from the web interface. You will have to study how to send it to the network though, but it is not hard
-
Looking at this myself, haven't tested yet though.
Appears that syslog-ng (an available package) will collect messages from text files. So similar to filebeats or splunkd, it should be able to read the files in from /usr/local/logs/current/. for remote delivery.
https://www.syslog-ng.com/technical-documents/doc/syslog-ng-open-source-edition/3.17/administration-guide/18#TOPIC-989607