Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Remote logging and DShield

    General pfSense Questions
    7
    15
    2.8k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      firewalluser
      last edited by

      No joy with this then? https://www.dshield.org/linux_clients.html#freebsd

      Capitalism, currently The World's best Entertainment Control System and YOU cant buy it! But you can buy this, or some of this or some of these

      Asch Conformity, mainly the blind leading the blind.

      1 Reply Last reply Reply Quote 0
      • telservT
        telserv
        last edited by

        Hi Firewalluser.

        I'll try your suggestion immediately, and let you know.

        Thanks

        1 Reply Last reply Reply Quote 0
        • telservT
          telserv
          last edited by

          Hi Firewalluser:

          I've investigated the FreeBSD choices on the DShield website.

          1.  FreeBSDshield looks like what I want, but is a dead link.  When searching for it on the internet, it does show up, but again the links have gone dead.

          2.  There is a text file with some scripts from 2004, but given their age, and my lack of ability with php,  I've decided not to try them.

          DShield is aware of the problem, and one of their handlers is looking at it.  He hasn't give me any specific analysis of why the existing systems don't work.

          Thanks for your efforts.

          1 Reply Last reply Reply Quote 0
          • Z
            zerodamage
            last edited by

            @Gord:

            Hi Firewalluser:

            I've investigated the FreeBSD choices on the DShield website.

            1.  FreeBSDshield looks like what I want, but is a dead link.  When searching for it on the internet, it does show up, but again the links have gone dead.

            2.  There is a text file with some scripts from 2004, but given their age, and my lack of ability with php,  I've decided not to try them.

            DShield is aware of the problem, and one of their handlers is looking at it.  He hasn't give me any specific analysis of why the existing systems don't work.

            Thanks for your efforts.

            The version that they support on the DShield site is FreeBSD 4.2 and we are now at 10.x so it is unlikely to work. Ideally there would be a package or something available on the pfSense system itself to handle this. I may post a bounty for this as I do not have the time to write one myself. Let me know if you want to contribute to the bounty.

            1 Reply Last reply Reply Quote 0
            • I
              iced
              last edited by

              someone done some work to fixing this but seems stalled at added the package https://github.com/Robert-Nelson/dshield-sensor-pfsense hopeful Robert Nelson will get it sorted

              1 Reply Last reply Reply Quote 0
              • R
                robertn
                last edited by

                I have all the work done. I fixed the dshield sensor scripts and created a pfsense package.  However after months of waiting for the package to be accepted by pfSense I gave up and closed the ticket and the pull request.

                1 Reply Last reply Reply Quote 0
                • V
                  va176thunderbolt
                  last edited by

                  I'd love to be able to submit my logs to dshield to help them - they've helped me a lot in the past. I had even considered sponsoring a bounty.

                  Can you share your package?

                  1 Reply Last reply Reply Quote 0
                  • R
                    robertn
                    last edited by

                    Unfortunately its a little more complicated than just sharing a package, you kinda have to go through the package manager which wants to talk to a package repository website.  Plus since its written in perl and pfsense doesn't have perl you need to install a pbi.

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      Why can you not just send your firewall logs from pfsense to syslog server, and then send the logs from there to dshield?

                      Don't they have a package that runs on windows and uses the kiwi syslog
                      https://www.dshield.org/windows_clients.html

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      1 Reply Last reply Reply Quote 0
                      • V
                        va176thunderbolt
                        last edited by

                        I run my installs on physcal hardware, and would prefer to run have to run additional boxes just for logging. Most of my pfsense boxes have plenty of spare cycles to bundle up logs and submit them to Dshield for their analysis.

                        1 Reply Last reply Reply Quote 0
                        • R
                          robertn
                          last edited by

                          The problem is not so much one of physically getting the data to dshield although that is part of it.  The main issue is parsing the logs and getting the information reformatted into the proper format for submission.  Remotely logging them just moves the problem to another machine, one that doesn't have the scripts builtin to pfsense to help with the parsing.

                          1 Reply Last reply Reply Quote 0
                          • I
                            iced
                            last edited by

                            Any Luck getting pfsense to include it,  looked as if there was a way to manual pull down perl, or maybe just turn it in to zip or tar with perl if pfsense

                            1 Reply Last reply Reply Quote 0
                            • Z
                              zerodamage
                              last edited by

                              Just bumping this back up. I think this should happen at some point.

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.