Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Dashboard 0.8.3 and Beyond, "Easy Rule" & FW Log Summary Graphs

    Scheduled Pinned Locked Moved pfSense Packages
    13 Posts 6 Posters 4.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G Offline
      grandrivers
      last edited by

      will some of this get commited to 2.0?
      that would be cool

      pfsense plus 25.03 super micro A1SRM-2558F
      C2558 32gig ECC  60gig SSD

      1 Reply Last reply Reply Quote 0
      • jimpJ Offline
        jimp Rebel Alliance Developer Netgate
        last edited by

        @grandrivers:

        will some of this get commited to 2.0?
        that would be cool

        That's on my to-do list. I'm hoping the backend stuff isn't all that different, but I haven't looked at it too deeply.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • jimpJ Offline
          jimp Rebel Alliance Developer Netgate
          last edited by

          Just pushed Dashboard 0.8.2 with a couple exciting new features.

          #1: Firewall Log Summary Graphs - very cool :)

          #2: Firewall Log filtering - There is a text box at the bottom of the firewall log that may be used to filter the results

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • AhnHELA Offline
            AhnHEL
            last edited by

            Great work Jimp!

            Loving all the improvements and added features.

            AhnHEL (Angel)

            1 Reply Last reply Reply Quote 0
            • jimpJ Offline
              jimp Rebel Alliance Developer Netgate
              last edited by

              I put up 0.8.3 last night, main thing is just a bug fix for the summary graphs but it was a big one, the data sets weren't being populated properly, so the graphs were wildly incorrect.

              Should be OK now.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • jimpJ Offline
                jimp Rebel Alliance Developer Netgate
                last edited by

                @grandrivers:

                will some of this get commited to 2.0?
                that would be cool

                FYI, this should all be in 2.0 now. I checked it in over the weekend.

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • S Offline
                  serialdie
                  last edited by

                  jimp,

                  One of the main futures I use from the dashboard is the Snort alert widget.
                  The login from snort change in the last build and broke the ability of the dashboard snort widgets to work.

                  Can you look in to it?

                  Thank You!

                  1 Reply Last reply Reply Quote 0
                  • jimpJ Offline
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    I'll see what I can do, but it may be a while before I can get to this. I don't know that I have snort up and running on any of my testing systems.

                    Do the alerts not show up at all?

                    Hopefully it's just something simple like the path to the log file changing…

                    Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 0
                    • S Offline
                      serialdie
                      last edited by

                      Actually is just a new option that Snort has… If you enable Full login it will fully change the way it logs...
                      Here is an example:

                      The new way:

                      [ ** ] [ 1:1394:10 ] SHELLCODE x86 inc ecx NOOP [ ** ] 
                      [ Classification: Executable code was detected ] [ Priority: 1 ] 
                      06/09-17:53:02.354113 76.13.218.11:80 -> 98.199.248.92:46980
                      TCP TTL:49 TOS:0x20 ID:63898 IpLen:20 DgmLen:1053 DF
                      AP Seq: 0x89245C0C Ack: 0xB5E7090E Win: 0x2DA0 TcpLen: 20

                      The old way:

                      06/09-18:07:07.870063 [ ** ] [ 1:1394:10 ] SHELLCODE x86 inc ecx NOOP [ ** ] [ Classification: Executable code was detected ] [ Priority: 1 ] {TCP} 76.13.222.11:80 -> 98.199.248.92:18772

                      But I did not notice that it was enabling the full login that broke it… I got it working again by disabling the full login option.

                      Thanks!

                      1 Reply Last reply Reply Quote 0
                      • jimpJ Offline
                        jimp Rebel Alliance Developer Netgate
                        last edited by

                        Probably best to leave things as they are then, rather than try to write up two different log parsers. As long as that solution is documented somewhere it should work out.

                        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                        Need help fast? Netgate Global Support!

                        Do not Chat/PM for help!

                        1 Reply Last reply Reply Quote 0
                        • T Offline
                          tester_02
                          last edited by

                          @serialdie:

                          But I did not notice that it was enabling the full login that broke it… I got it working again by disabling the full login option.

                          Thanks!

                          Where is the option to disable that option?????

                          1 Reply Last reply Reply Quote 0
                          • M Offline
                            matrix200
                            last edited by

                            Yeah I also would like to know how to disable full logging.
                            After the last upgrade I have the same issue here (not working with dashboard and look different in snort logs tab).

                            Ok I still don't know how to do that via the gui but I modified snort.conf by replacing
                            output alert_full: alert
                            with
                            output alert_fast: alert
                            and then restarted snort.
                            That did the trick.

                            Current network "hardware" :
                            Running 2.2RC in Virtualbox 4.2.16.

                            Retired:
                            ALIX2C2 , 4 gigabyte disk cf card running 2.0 (official release).

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.