pf ipv4 syslog-ng parser available
-
I wrote a very basic parser using syslog-ng's patterndb to enable readability of pass/block/match logs from pfsense, so I am making it available in github if someone needs it. There's also a very basic logstash config -- just enough to do GeoIP and send it to elastic. Both are easily modifiable.
https://github.com/lsampas/pfsense-syslog-ng
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.