Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to send rule name to syslog?

    Scheduled Pinned Locked Moved General pfSense Questions
    12 Posts 2 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L Offline
      lutel
      last edited by

      Why then labels are not included in the log events? Addresses or protocol names is also not unique, yet these are included in the logs. To me lack of this really basic feature is ridicolous for product which is so mature. I can't name any other firewall product which can't send rule names/labels in logs (CheckPoint, PaloAlto, Juniper, Dlink - they all can do it since start). This is really weird as the information is accessible locally (even in the log view), but can't be send to remote logging server, this is absurd.

      1 Reply Last reply Reply Quote 0
      • D Offline
        doktornotor Banned
        last edited by

        I didn't write it, don't ask me. The remote syslogs are broken incompatible crap anyway, syslogd completely sucks for this.

        https://redmine.pfsense.org/issues/1940

        1 Reply Last reply Reply Quote 0
        • L Offline
          lutel
          last edited by

          What do you mean by incompatibile crap? Are there any other available connectors to remote log servers? The connector itself works fine, however logging format is just crap.

          1 Reply Last reply Reply Quote 0
          • D Offline
            doktornotor Banned
            last edited by

            As referenced on the bug above. Sending logs in cleartext is something that immediately makes the entire feature useless for tons of people. In addition to that - as soon as you start this remote logging from a bunch of different OSes or even OS versions on some syslog server, you just get a giant piece of mess where you don't even know where it came from in the first place (such as the hostname missing). That's the entire experince I've got from playing with central logging of stuff from various routers/NAS boxes and servers. RFC-3164 is just sci-fi. Waste of time.

            1 Reply Last reply Reply Quote 0
            • L Offline
              lutel
              last edited by

              I see, the syslog can be probably stunneled, but lack of source hostname, damn… pfSense logging is just crap.

              1 Reply Last reply Reply Quote 0
              • D Offline
                doktornotor Banned
                last edited by

                It's not just pfSense; this is incompatible crap in general. What I can recommend

                • install syslog-ng package
                • configure as required
                • get the logs rotated as required
                • pull the rotated archived logs from the box
                • store/parse/do whatever else needed with those

                Push approach -> miserable fail.

                1 Reply Last reply Reply Quote 0
                • L Offline
                  lutel
                  last edited by

                  Even with syslog-ng I still wont be able to get proper event fields (like rule label). Its fairly easy to make some workarounds for stream encryption and even for hostname (can be done with syslog-ng), but lack of important fields in event logs is just pure pfSense crap.

                  1 Reply Last reply Reply Quote 0
                  • D Offline
                    doktornotor Banned
                    last edited by

                    Afraid you are barking up the wrong tree here. It simply ain't supported by pflog(4) at all. Install whatever FreeBSD system and you won't get any labels logged either.

                    1 Reply Last reply Reply Quote 0
                    • L Offline
                      lutel
                      last edited by

                      It looks that pfSense adds many fields to pfLog structure (like anchor text), they could make it in the GUI (where logs are processed and include rule name), they could do it in syslog stream as well.

                      1 Reply Last reply Reply Quote 0
                      • D Offline
                        doktornotor Banned
                        last edited by

                        Good luck waiting for this…

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.