Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfctl -s states like tail -f

    Scheduled Pinned Locked Moved General pfSense Questions
    17 Posts 6 Posters 1.2k Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ Offline
      johnpoz LAYER 8 Global Moderator
      last edited by

      "so I can redirect text to file.log and grep after one day"

      Seems like he wants to log every state as created..

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 25.07 | Lab VMs 2.8, 25.07

      1 Reply Last reply Reply Quote 0
      • stephenw10S Offline
        stephenw10 Netgate Administrator
        last edited by

        Ha, it would help if I managed to read the first post in it's entirety I guess.  ::)

        Ok….

        1 Reply Last reply Reply Quote 0
        • T Offline
          tonysud
          last edited by

          @johnpoz:

          Seems like he wants to log every state as created..

          YES, It's exactly what I want to do

          1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator
            last edited by

            wouldn't it just be easier to log your allowed traffic and send that to syslog?

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.07 | Lab VMs 2.8, 25.07

            1 Reply Last reply Reply Quote 0
            • T Offline
              tonysud
              last edited by

              for me it's easier to read

              1 Reply Last reply Reply Quote 0
              • jimpJ Offline
                jimp Rebel Alliance Developer Netgate
                last edited by

                There is no way to do what you're after as-is.

                You could maybe rig something up with just the right tcpdump parameters against the pflog interface or maybe use pfsync in some way, but we don't have anything in place that would log state activity in a way that would give you what you're after.

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • K Offline
                  kpa
                  last edited by

                  You could possibly look at how the pflogd daemon is implemented and roll your own version that does the same for the state tables.

                  https://svnweb.freebsd.org/base/releng/11.1/contrib/pf/pflogd/

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S Offline
                    stephenw10 Netgate Administrator
                    last edited by

                    Mmm, that may be possible. Seems quite extreme though.  ;)

                    I would think that adding logging and an appropriate description on the pass rules you want to know about would allow you filter exported logs. Simply exporting them to a log analyser may be good enough for what you want to see.

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • T Offline
                      tonysud
                      last edited by

                      Simply exporting them to a log analyser may be good enough for what you want to see.

                      is there a free log analyser for pfsense log?

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S Offline
                        stephenw10 Netgate Administrator
                        last edited by

                        Graylog seems pretty popular though I've not used it myself.

                        There are a number of detailed write-ups out there for different solutions, I guess it depends how deep you want to go.

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • T Offline
                          tonysud
                          last edited by

                          no updates?
                          in linux thereis conntrack -E command which does what I need
                          no alternative for pfsense?

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.