Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Sarg package for pfsense

    Scheduled Pinned Locked Moved pfSense Packages
    467 Posts 99 Posters 499.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • marcellocM
      marcelloc
      last edited by

      @stramato:

      Should I do anything special config to make it work?

      yes, check all sarg config options, reports to generate and create a schedule to run.

      Default sarg options has (yes) after it's description. Select all to create a default config.

      Treinamentos de Elite: http://sys-squad.com

      Help a community developer! ;D

      1 Reply Last reply Reply Quote 0
      • S
        stramato
        last edited by

        @marcelloc:

        @stramato:

        Should I do anything special config to make it work?

        yes, check all sarg config options, reports to generate and create a schedule to run.

        Default sarg options has (yes) after it's description. Select all to create a default config.

        Thank you. I had to simply select (ctrl+click to highlight) the config options then click save. I got confused because I thought they're already enabled since they already have a (yes) on them.

        1 Reply Last reply Reply Quote 0
        • C
          ckuecker
          last edited by

          I have Sarg running on multiple pfsense boxes.  One of my boxes has about 100 users behind it and the report will only work for about the first 4 hours after I wipe out the squid logs.  After that I am guessing the squid log gets too big and the sarg report will no longer work.

          I am using the -d arguments and I have tried limiting the number of users.

          Any suggestions on how I can get sarg to accept a larger log file?

          1 Reply Last reply Reply Quote 0
          • marcellocM
            marcelloc
            last edited by

            @ckuecker:

            Any suggestions on how I can get sarg to accept a larger log file?

            I have large files working fine.

            try to run sarg on console to check what it returns.

            Treinamentos de Elite: http://sys-squad.com

            Help a community developer! ;D

            1 Reply Last reply Reply Quote 0
            • C
              ckuecker
              last edited by

              @marcelloc:

              @ckuecker:

              Any suggestions on how I can get sarg to accept a larger log file?

              I have large files working fine.

              try to run sarg on console to check what it returns.

              Seems to be working fine now.  I just need to figure out my schedule because, like others my report is pretty empty at 00:00.  I need to figure out Cron now.

              I have highlighted what I am questioning.  Is this rotating my squid logs even after I have set them not to rotate?

              ![cron sarg.PNG](/public/imported_attachments/1/cron sarg.PNG)
              ![cron sarg.PNG_thumb](/public/imported_attachments/1/cron sarg.PNG_thumb)

              1 Reply Last reply Reply Quote 0
              • marcellocM
                marcelloc
                last edited by

                Check on squid config because it's not created by sarg.

                Treinamentos de Elite: http://sys-squad.com

                Help a community developer! ;D

                1 Reply Last reply Reply Quote 0
                • C
                  ckuecker
                  last edited by

                  @marcelloc:

                  Check on squid config because it's not created by sarg.

                  This is my squid config.  Rotation should be disabled.

                  Capture.PNG
                  Capture.PNG_thumb

                  1 Reply Last reply Reply Quote 0
                  • C
                    ckuecker
                    last edited by

                    I think it is working now.  Thanks for all your help Marcelloc

                    1 Reply Last reply Reply Quote 0
                    • C
                      ckuecker
                      last edited by

                      Marcelloc,  I am not sure if this is a bug or if I am doing something / missing something.

                      I would like to provide access to the Sarg reports to a few users.  When I give them permissions via the user manager to the Sarg reports, it does not work fully.
                      The real time logs work, but when you try and view reports it just flickers non stop.  Looks like it is trying to load the sarg reports frame inside the sarg reports frame.

                      Attached is the permissions I am giving the user.  Is there an easier way or is this a bug?

                      permissions.PNG
                      permissions.PNG_thumb

                      1 Reply Last reply Reply Quote 0
                      • marcellocM
                        marcelloc
                        last edited by

                        @ckuecker:

                        Looks like it is trying to load the sarg reports frame inside the sarg reports frame.

                        Reinstall sarg package, I've fixed it last week.

                        Treinamentos de Elite: http://sys-squad.com

                        Help a community developer! ;D

                        1 Reply Last reply Reply Quote 0
                        • C
                          ckuecker
                          last edited by

                          awesome!   Thanks!!

                          edit:  works like a charm!

                          1 Reply Last reply Reply Quote 0
                          • L
                            LoZio
                            last edited by

                            Using nano 2.0.1 and SARG 2.3.2 pkg v.0.6.1.
                            No matter what I do, tried everithing I found in this forum.
                            I always get
                            Error: Could not find report index file.
                            Check and save sarg settings and try to force sarg schedul

                            Running sarg -x results in

                            SARG: sarg version: 2.3.2 Nov-23-2011
                            SARG: Reading access log file: /var/squid/logs/access.log
                            SARG: Records in file: 11460, reading: 100.00%
                            SARG:    Records read: 11460, written: 11459, excluded: 0
                            SARG: Squid log format
                            SARG: Period: 22 Oct 2012
                            SARG: pre-sorting files
                            SARG: File /usr/local/sarg-reports/22Oct2012-22Oct2012 already exists, moved to /usr/local/sarg-reports/22Oct2012-22Oct2012.4
                            SARG: Cannot delete /usr/local/sarg-reports/22Oct2012-22Oct2012/d192_168_7_11.html - No such file or directory

                            Saved, re-saved, re-re-re-saved the config with (yes) options.
                            Deleted and recreated report directories, gave them 777. Created a schedule with every possible combination of parameters, run it manually, scheduled,…
                            Each time the no index error.

                            Running a schedule results in
                            php: /pkg_edit.php: The command '/usr/local/bin/sarg ' returned exit code '1', the output was 'SARG: Records in file: 11647, reading: 0.00%^MSARG: Records in file: 5000, reading: 42.93%^MSARG: Records in file: 10000, reading: 85.86%^MSARG: Cannot delete /usr/local/sarg-reports/22Oct2012-22Oct2012/d192_168_7_11.html - No such file or directory SARG: Records in file: 11647, reading: 100.00%'

                            If something is written in these forums, I tried it. :(
                            Realtime works correctly but what I need i history data.
                            Any other test/debug I can try?

                            1 Reply Last reply Reply Quote 0
                            • marcellocM
                              marcelloc
                              last edited by

                              what config and report options did you selected?

                              this is my current config

                              sarg_options.png
                              sarg_options.png_thumb

                              Treinamentos de Elite: http://sys-squad.com

                              Help a community developer! ;D

                              1 Reply Last reply Reply Quote 0
                              • W
                                wdowney
                                last edited by

                                I had the same problem as LoZio. To get mine to work I did the following -

                                • de-selected all of the options on the general tab and saved it
                                • forced an update on the schedule tab
                                • re-selected the options on the general tab and saved it
                                • forced an update on the schedule tab

                                This caused the index.html file to be generated in my /usr/local/sarg-reports folder. Up until this point everything else was working except for the index.html file.

                                1 Reply Last reply Reply Quote 0
                                • H
                                  hermanleao
                                  last edited by

                                  @marcelloc:

                                  Hi all,

                                  I've just published sarg package for pfsense with squid,squidguard and dansguardian log Analysis as well real time report tab.

                                  Squidguard functions are under devel yet but squid and dansguardians(as well as I tested) are working.

                                  After almost everything done, I found an old sarg package published on forum by joaohf and merged some function calls from this old thread.

                                  Another good point is that sarg is able to forward logs via email, so I'm planning to include it for nanobsd installs.

                                  have fun and feedback!  :)

                                  att,
                                  Marcello Coutinho

                                  Thanks a lot!

                                  1 Reply Last reply Reply Quote 0
                                  • N
                                    Nachtfalke
                                    last edited by

                                    Hi,

                                    I would like to use sarg package to get a better overview of the blocked sites from squidguard.
                                    I do not have logging enabled on squid - just on squidguard to watch the blocked sites.

                                    In my company it is not allowed to log accessed sites. The log view of squidguard is not the best I think and so I would like to use squidguard.

                                    On the sarg "general" tab I selected "squidguard" and so options on the multiple-choise lists. When saving the settings I got an error on the top right corner that the squid/access.log was not found.

                                    I took a look at the sarg.inc and I think the problem could be somewhere on line 230. But I am not sure. I added a "break;" but without luck.

                                    So my questions are:
                                    Is it possible to use sarg to just "analyse" the blocked.log file of squidguard but no other log files ?

                                    Any help would be appreciated :-)

                                    1 Reply Last reply Reply Quote 0
                                    • marcellocM
                                      marcelloc
                                      last edited by

                                      @Nachtfalke:

                                      So my questions are:
                                      Is it possible to use sarg to just "analyse" the blocked.log file of squidguard but no other log files ?

                                      Hi Nachtfalke,

                                      I've enabled squidguard config options on gui, but I do not use squidguard. take a look on sarg config options and check manually how it should be configured to work with squidguard. I'll push a fix if you find a way to get it working only with squidguard reports.

                                      The missing break was intentional as it requires squid to work.

                                      att,
                                      Marcello Coutinho

                                      Treinamentos de Elite: http://sys-squad.com

                                      Help a community developer! ;D

                                      1 Reply Last reply Reply Quote 0
                                      • N
                                        Nachtfalke
                                        last edited by

                                        I changed the following code on sarg.inc starting on line 227:
                                        From:

                                        
                                        		case 'squidguard':
                                        			$squidguard_conf='squidguard_conf '.$sarg_proxy['squidguard_config'];
                                        			$redirector_log_format='redirector_log_format #year#-#mon#-#day# #hour# #tmp#/#list#/#tmp#/#tmp#/#url#/#tmp# #ip#/#tmp# #user# #end#';
                                        			#Leve this case without break to include squid log file on squidguard option
                                        
                                        

                                        To:

                                        
                                        		case 'squidguard':
                                        			$access_log= $sarg_proxy['squidguard_block_log'];
                                        			$squidguard_conf='squidguard_conf '.$sarg_proxy['squidguard_config'];
                                        			$redirector_log_format='redirector_log_format #year#-#mon#-#day# #hour# #tmp#/#list#/#tmp#/#tmp#/#url#/#tmp# #ip#/#tmp# #user# #end#';
                                        			#Leve this case without break to include squid log file on squidguard option
                                        		break;
                                        
                                        

                                        Now I got this error on system log:

                                        
                                        Nov 30 21:53:47 	squid[41070]: Squid Parent: child process 41365 started
                                        Nov 30 21:53:46 	squid[30925]: Squid Parent: child process 28838 exited with status 0
                                        Nov 30 21:53:42 	php: /pkg_edit.php: The command '/usr/local/bin/sarg ' returned exit code '1', the output was 'SARG: Records in file: 30911, reading: 0.00%^MSARG: Maybe you have a broken amount of data in your /var/squidGuard/log/block.log file SARG: getword loop detected after 255 bytes. SARG: Line="2012-11-12 17:40:37 [49110] Request(Einge_Internet/none/-) http://tools.google.com/service/update2?w=6:Ihy13C0hp8xIICE3I3l36cwhjObjYjH-7ezo0Kwjmqdp2WQIYaHezKLduIFlOC07QuSuqJStljIF_EJvqlNqH0mGJEvVnkreJQ2qbW71ZWEQEq24CssCY5d9Ij2SpjptLVmxkQea7O1ZlFABARa472hYaKBlD-inQ1Tv_mhFcwGtSnWPlcze4nm8kf-U3F9frIL5ODG5pU6wvGJhMf50_KfRnn_LxvTASxdUPr_pmKRUeElE6XcQz4FfZJtJxQFcuscJFDwxRAKgT4V4rztyV7DbVScLMNy5y_OfKwesqun5J5bg093aLt-twEi8bFZNxjQnPQSUqYuNivTmpnyQFw 172.17.183.27/- - POST REDIRECT" SARG: Record="http://tools.google.com/service/update2?w=6:Ihy13C0hp8xIICE3I3l36cwhjObjYjH-7ezo0Kwjmqdp2WQIYaHezKLduIFlOC07QuSuqJStljIF_EJvqlNqH0mGJEvVnkreJQ2qbW71ZWEQEq24CssCY5d9Ij2SpjptLVmxkQea7O1ZlFABARa472hYaKBlD-inQ1Tv_mhFcwGtSnWPlcze4n
                                        Nov 30 21:53:42 	php: /pkg_edit.php: Sarg: force refresh now with args, compress() and restart action after sarg finish.
                                        Nov 30 21:53:32 	php: /pkg_edit.php: [sarg] sarg_xmlrpc_sync.php is starting.
                                        
                                        

                                        Not sure what that means ?

                                        PS: Why is xmlrpc sync starting but I did not enable that !?

                                        1 Reply Last reply Reply Quote 0
                                        • marcellocM
                                          marcelloc
                                          last edited by

                                          @Nachtfalke:

                                          Not sure what that means ?

                                          Maybe a too long line

                                          @Nachtfalke:

                                          PS: Why is xmlrpc sync starting but I did not enable that !?

                                          Maybe a print message before the if  :)

                                          move

                                          log_error("[sarg] sarg_xmlrpc_sync.php is starting."); 
                                          

                                          from line 441 to 445 after

                                          if(!$synconchanges)
                                                          return;
                                          
                                          

                                          Treinamentos de Elite: http://sys-squad.com

                                          Help a community developer! ;D

                                          1 Reply Last reply Reply Quote 0
                                          • L
                                            LinuxTracker
                                            last edited by

                                            2.0.1 Release x86 w/ latest Sarg (which is working pretty well)

                                            Was a solution found for the LDAP issue?  I've read the thread a few times and didn't see anything definitive.

                                            I've tried every GUI config possible, forcing updates over and over, tweaking the conf file, reinstalled Sarg, restarted pfSense. etc.

                                            I ran the packet sniffer on the LAN adapter for hours and ran another one on the AD LDAP server.
                                            No port 389 traffic from the pfSense box at all.
                                            From what I see, LDAP is dead.

                                            I'll keep trying but I'm not sure where to look next.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.