Sarg package for pfsense
-
Went the nanobsd arrive I will help testing, thanks :)
squid 2.x does not log on nanobsd installs.
Are you running dansguardian?
-
I enable logs in nanobsd and have been using sarg for a while with success, thanks!!!
-
great! :)
I'll commit squidguard functions to sarg until friday.
-
Hi Marcello,
will you (or is there) include a method to sort the reports? For example, when viewing "top sites", it sorts the list by amount of 'hits' by default, I'd like to sort by amount of data transferred if possible.
with the proliferation of web apps, hits don't really mean as much as they once did in these types of reports. as an example I've seen one user generate over 20k hits on teamviewer.com in one day.
thanks again,
greg -
Hi Marcello,
will you (or is there) include a method to sort the reports? For example, when viewing "top sites", it sorts the list by amount of 'hits' by default, I'd like to sort by amount of data transferred if possible.
with the proliferation of web apps, hits don't really mean as much as they once did in these types of reports. as an example I've seen one user generate over 20k hits on teamviewer.com in one day.
thanks again,
greg@marcelloc there is a way to sort that is built in, kinda… check the default conf file for 'TAG: sorttable path'. Javascript sorttable.js would need to be added, from http://www.kryogenix.org/code/browser/sorttable/.
-
Thanks cino.
I'm merging a contribution for squidguard reports from ccesario and then I'll take a look on it.
-
report on firefox no work!!! ??? fine on google chrome ;D
-
report on firefox no work!!! ??? fine on google chrome ;D
What version of firefox? I'm using it on firefox11 and chrome without issues.
-
@marcelloc there is a way to sort that is built in, kinda… check the default conf file for 'TAG: sorttable path'. Javascript sorttable.js would need to be added, from http://www.kryogenix.org/code/browser/sorttable/.
I'll try to include this javascript to enable sort change on reports but did you saw user sort field on sarg settings?
-
I've managed to get Sarg Realtime working but when I try and "View Reports", I get a blank page:
-
Try to generate another report after selecting indextree on sarg settings.
-
sarg 0.3 is out with date report format ,sortable reports and squidguard. :)
Thanks to cino and ccesario.
-
report on firefox no work!!! ??? fine on google chrome ;D
What version of firefox? I'm using it on firefox11 and chrome without issues.
I'm using firefox 11 and does not display my report, if it works well with chrome
-
bitskiller,
did you tried to refresh the report frame using right-click -> this frame -> reload?
-
Try to generate another report after selecting indextree on sarg settings.
Thanks, that did it, I now have reports showing.
-
I really interesting SARG but until now I could not find any e-mail option to use it for system log report.
Thank u
-
It's not implemented yet.
Mail option will need a mailer daemon running on pfsense like postfix forwarder.
-
It's not implemented yet.
Mail option will need a mailer daemon running on pfsense like postfix forwarder.
I have tested SARG many time with Squid-reverse. This is my step
1. I have installed Squid-reverse.
2. I have installed SARG and after that I got some error: Sarg config error:log file () does not exits. I want to know what is wrong?.
3. I tried to change the "userid" or the "ip address" to be a real user name on the reports like this: "172.31.21.22 Donny Van Cooper" but in the "View report and realtime"tab it does not show a real user name. Where can I resolve any ip address on pfSense or I have to resolve any ip address on Domain Controller (Windows Server 2008)
4. I use Firefox web browser also Google Chrome for config SARG and at the "view report" tab dat you said to do is "This frame > reload frame" but some time it does not work I have to do again and again or I have to wait a few second and then report appear.
5. Do I have only to select interface "LAN" or I have to select both "LAN and loopback on Squid-reverse.Thank u very much
-
2. I have installed SARG and after that I got some error: Sarg config error:log file () does not exits. I want to know what is wrong?.
This maybe a first install bug, I'll check it.
3. I tries to change the "userid" or the "ip address" to be a real user name on the reports like this: "172.31.21.22 Donny Van Cooper" but in the "View report and realtime"tab it does not show a real user name. Where can I resolve any ip address on pfSense or I have to resolve any ip address on Domain Controller (Windows Server 2008)
4. I use Firefox web browser also Google Chrome for config SARG and at the "view report" tab dat you said to do is "This frame > reload frame" but some time it does not work I have to do again and again or I have to wait a few second and then report appear.did you created any schedule on sarg to create reports?
5. Do I have only to select interface "LAN" or I have to select both "LAN and loopback on Squid-reverse.
Just lan for normal use.
-
2. I have installed SARG and after that I got some error: Sarg config error:log file () does not exits. I want to know what is wrong?.
This maybe a first install bug, I'll check it.
3. I tries to change the "userid" or the "ip address" to be a real user name on the reports like this: "172.31.21.22 Donny Van Cooper" but in the "View report and realtime"tab it does not show a real user name. Where can I resolve any ip address on pfSense or I have to resolve any ip address on Domain Controller (Windows Server 2008)
4. I use Firefox web browser also Google Chrome for config SARG and at the "view report" tab dat you said to do is "This frame > reload frame" but some time it does not work I have to do again and again or I have to wait a few second and then report appear.did you created any schedule on sarg to create reports?
5. Do I have only to select interface "LAN" or I have to select both "LAN and loopback on Squid-reverse.
Just lan for normal use.
Yes, Marcelloc. I have created schedule on sarg to create reports. you can see my screenshot pictures that I post its here but a real user name is still not work.
Thank a lot for your help
-
check create index tree by file too onsarg config and force a report update.
-
check create index tree by file too on sarg config and force a report update.
Hello Marcelloc, I have done what you say but a real user name still not work. as the screenshot below.
Thank u very much. I am tired, I go to bed now.
-
Donny,
Thanks for your feedback.
I found an error on field check that was preventing user file to be created.
I'm fixing it and including some other options before publishing.
-
Version 0.4 is out with
-
usertab fix
-
charset option field
-
few more report config options
As users has its own tab, you may need to backup your sarg user configuration before update(just in case ;))
-
-
Version 0.4 is out with
-
usertab fix
-
charset option field
-
few more report config options
As users has its own tab, you may need to backup your sarg user configuration before update(just in case ;))
Hello Marcelloc, today is a wonderful world, I have tested SARG with a real user name for a new SARG v.04. Now it is working. see some screenshot. I will waiting for the next e-mail option to use for system log sending. The next step I will testing with Windows Server 2008 R2 Active Directory ( LDAP ). You are really really working hard. If I find something error more I will posting here as soon as possible.
Thank u so much to help me a lot
-
-
Hi,
i updated today and now have:
sarg [Sarg] config error: dansguardian logfile () does not exist
-
Hi,
i updated today and now have:
sarg [Sarg] config error: dansguardian logfile () does not exist
It happens just after reinstall or on every Sargent configuration save?
-
reinstalling only.
[SOLVED] i also experience if i set up a schedule, and do a 'Force Update Now' i get no report, telling me:
Error: Could not find report index file. Check sarg settings and try to force sarg schedule.
in system logs i see:
Apr 10 15:55:45 php: /pkg_edit.php: The command '/usr/local/bin/sarg ' returned exit code '1', the output was 'SARG: Records in file: 174067, reading: 0.00%^MSARG: Maybe you have a broken date in your /var/log/dansguardian/access.log file SARG: getword_atoll loop detected after 2 bytes. SARG: Line="xx.xx.xx.xx http" SARG: Record="xx.xx.xx.xx http" SARG: searching for 'x2f''
i deleted access.log and restarted dansguradian, everythings fine again. :)
-
sarg reads dansguardian logs only in squid format.
A log rotate(or remove like you did :)) should fix it after changing format.
-
Hi,
I just wonder, how can I map users name with dynamic IP address if my pfSense act as DHCP Server? Is it possible? In this case I do not use Windows Server.
example: I have 75 users desktop Windows XP or Windows 7 and get dynamic ip address from pfSense DHCP server or I have to map a real user name with ip address one by one at the option "Users association" like this:
172.31.21.22 Don Van Cooper
172.31.21.23 Teun Van Laarhoven
172.31.21.24 Marijon Kooijstra > until 75 users.pfSense:
1. pfSense is DNS Server
2. pfSense is DNS Forwarder
3. pfSense is DHCP Serverat option "Ntlm User Format" When I have changed from "domainname+username(default)" to "Username" and Realtime report is not working. what is differences between "domainname+username" and "Username" to use?
-
Hi,
I just wonder, how can I map users name with dynamic IP address if my pfSense act as DHCP Server? Is it possible? In this case I do not use Windows Server.
example: I have 75 users desktop Windows XP or Windows 7 and get dynamic ip address from pfSense DHCP server or I have to map a real user name with ip address one by one at the option "Use association" like this:
172.31.21.22 Don Van Cooper
172.31.21.23 Teun Van Laarhoven
172.31.21.24 Marijon Kooijstra > until 75 users.Try to enable squid basic authentication with local users.
at option "Ntlm User Format" When I have changed from "domainname+username(default)" to "Username" and Realtime report is not working. what is differences between "domainname+username" and "Username" to use?
This option is usefull only when you have ntlm authentication using samba and active directory.
-
Hi,
I just wonder, how can I map users name with dynamic IP address if my pfSense act as DHCP Server? Is it possible? In this case I do not use Windows Server.
example: I have 75 users desktop Windows XP or Windows 7 and get dynamic ip address from pfSense DHCP server or I have to map a real user name with ip address one by one at the option "Use association" like this:
172.31.21.22 Don Van Cooper
172.31.21.23 Teun Van Laarhoven
172.31.21.24 Marijon Kooijstra > until 75 users.Try to enable squid basic authentication with local users.
at option "Ntlm User Format" When I have changed from "domainname+username(default)" to "Username" and Realtime report is not working. what is differences between "domainname+username" and "Username" to use?
This option is usefull only when you have ntlm authentication using samba and active directory.
Thank u Marcelloc, One more question. When I have changed from "domainname+username(default)" to "Username" and why a realtime report is not working?
-
Thank u Marcelloc, One more question. When I have changed from "domainname+username(default)" to "Username" and why a realtime report is not working?
this is a config bug in sarg
config file says:
TAG: ntlm_user_format username|domainname+username
NTLM users format.
#ntlm_user_format domainname+username
ntlm_user_format usernamebut sarg returns with:
SARG: Unknown value "username" for parameter "ntlm_user_format"if I change this option to 'user' it works.
I'm publishing a patch right now, whait 15 minutes and reinstall sarg
-
Thank u Marcelloc, One more question. When I have changed from "domainname+username(default)" to "Username" and why a realtime report is not working?
this is a config bug in sarg
config file says:
TAG: ntlm_user_format username|domainname+username
NTLM users format.
#ntlm_user_format domainname+username
ntlm_user_format usernamebut sarg returns with:
SARG: Unknown value "username" for parameter "ntlm_user_format"if I change this option to 'user' it works.
I'm publishing a patch right now, whait 15 minutes and reinstall sarg
Now I do a basic to authenticate and create local user on Squid-reverse. At authentication settings, they say that I have to turn off "Transparent proxy" and I have done it.
at shedule tab I try to "force Update now" but at realtime report tab when I click "Show log", it does not show any report. It does not work when I use local user and authetication:local.
-
After disabling transparente proxy, you are able to filter ssl but you need first to configure proxy settings on client browsers.
-
After disabling transparente proxy, you are able to filter ssl but you need first to configure proxy settings on client browsers.
at the web browsers client I have configured proxy setting and I tried to log in with local user name and password that I created from Squid proxy. after log in success I try to check at realtime report on SARG but the report only show ip address and it is not show user name that I used log in.
-
Are you using just squid?
Can you check in log files if you can see the auth user?
-
Thanks Marcelo…
I've got some problem to get it done...
It doesn't work for me...
Can you help me?[Sarg]Sarg config error: log file () does not exists .:.
Apr 10 23:00:29 php: /pkg_edit.php: executing squid log rotate after sarg.
Apr 10 23:00:29 php: /pkg_edit.php: executing squidguard log rotate after sarg.
Apr 10 23:00:29 php: /pkg_edit.php: The command '/usr/local/bin/sarg ' returned exit code '1', the output was 'SARG: Records in file: 49003, reading: 0.00%^MSARG: Records in file: 5000, reading: 10.20%^MSARG: Records in file: 10000, reading: 20.41%^MSARG: Records in file: 15000, reading: 30.61%^MSARG: Records in file: 20000, reading: 40.81%^MSARG: Records in file: 25000, reading: 51.02%^MSARG: Records in file: 30000, reading: 61.22%^MSARG: Records in file: 35000, reading: 71.42%^MSARG: Records in file: 40000, reading: 81.63%^MSARG: Records in file: 45000, reading: 91.83%^MSARG: Cannot delete /usr/local/www/sarg-reports/08Apr2012-10Apr2012/d192_168_1_106.html - No such file or directory SARG: Records in file: 49003, reading: 100.00%'
Apr 10 23:00:28 php: /pkg_edit.php: Sarg: force refresh now with '' args and rotate action after sarg finish.Command line
sarg
SARG: Records in file: 49194, reading: 100.00%
SARG: Cannot delete /usr/local/www/sarg-reports/2012/04/08-10/d192_168_1_106.html - No such file or directory -
Can you clean this problematic folder and try to run Sarg again?
My current schedules are
1h with no action after sarg
1d with rotate and restart.Index options are selected on sarg configuration as well report overwrite.
-
Are you using just squid?
Can you check in log files if you can see the auth user?
First I have uninstall SARG and Squid-reverse because It is not work. After that I tried to install normal Squid-proxy and SARG again. When I created local user on Squid-proxy, I can not use capital and small letter like this: "Donny" but just only small letter: "donny" if I try to login via web browsers otherwise I can not login.
Now I turn off authenticate and go back to use "Transparent proxy" again. I will check log file in this evening and test again. I have to go to work now. bye
Thank u Marcelloc