Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Monitoring FW logs and attacks

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 2 Posters 3.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      skipper
      last edited by

      Hi folks,

      I want to monitor the FW logs (and attacks as well) on pfSense and I was looking if there is any tool on available packages where I can see the logs of the last month, and sort them by source/destination IP or destination port, but there is nothing like that as I can see.

      I want to be able the see which source/destination IPs, destination ports, have the most block packages, on all interfaces.
      Generally I want to be able to check the logs from some days ago and see if there was some attack and or so.

      Is there any way/tool on pfSense which I can use to have this function?

      thnx in advance

      1 Reply Last reply Reply Quote 0
      • G Offline
        galaxy60
        last edited by

        Hi I use syslog to another PC the software I am currently using is SYSLOG Watcher. intall the software on your PC and then on pfSense goto system logs settings and enable the tick box and enter your PC's IP address.

        1 Reply Last reply Reply Quote 0
        • S Offline
          skipper
          last edited by

          hi galaxy60,
          thnx for your reply

          that looks a good solution, do you maybe know any software like SYSLOG Watcher for linux (ubuntu)?
          have you compared the logs on SYSLOG Watcher and pfSense to see how fast/often are the logs being copied to the log server?

          I am thinking to enable also snort, is there something similar for sending snort logs as well?

          1 Reply Last reply Reply Quote 0
          • G Offline
            galaxy60
            last edited by

            Hi Linux has it's package you can install for syslog but I'm don't think it has a GUI like the one mentioned as for Snort this does have it own internal logging

            1 Reply Last reply Reply Quote 0
            • S Offline
              skipper
              last edited by

              thnx for your reply galaxy60,

              I guess I have to activate/enable snort and see how it is going with blocking/alerting/logging and then decide if I need to copy the logs to some other server as well.

              cheers

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.