Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Interpreting the raw firewall log

    Scheduled Pinned Locked Moved Firewalling
    10 Posts 4 Posters 3.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C Offline
      chaycock
      last edited by

      Is there a guide or information somewhere that explains how to interpret the raw firewall log entries that look like this:

      9,16777216,,1000000103,em2,match,block,in,4,0x0,,128,6846,0,none,17,udp,63,192.168.20.100,192.168.20.1,57942,53,43

      Thanks,
      Carlton

      1 Reply Last reply Reply Quote 0
      • DerelictD Offline
        Derelict LAYER 8 Netgate
        last edited by

        https://doc.pfsense.org/index.php/Filter_Log_Format_for_pfSense_2.2

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • C Offline
          chaycock
          last edited by

          Thank you, I totally missed that page.

          1 Reply Last reply Reply Quote 0
          • C Offline
            chaycock
            last edited by

            I was looking around the Status->System Log->Firewall log and noticed that you can have the system format the message in a much easier to read format for display.
            Is there a way to get that formatted message sent out via syslog instead of just the raw one?  I have syslog configured and I am getting messages, they are just in the raw format, it would be much easier to see what is going on when glancing at syslog if I could get the system to send the formatted message instead of the raw one.

            1 Reply Last reply Reply Quote 0
            • C Offline
              chaycock
              last edited by

              I have another question regarding some of the fields.  So here is the start of a partial log entry:

              71,16777216,,1000002665,em1

              According to the documentation page, the fields would be as follows:

              Rule Number=71
              Sub rule number=16777216
              Anchor=
              Tracker=1000002665
              Real interface=em1

              So when looking at the firewalls in the GUI, how do I determine the rule number so I can correlate it to the log?
              Also, what exactly is a 'sub rule' and why is the number so large?

              Thanks,
              Carlton

              1 Reply Last reply Reply Quote 0
              • DerelictD Offline
                Derelict LAYER 8 Netgate
                last edited by

                Click on the icon at the left (usually a block) to get the tag.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • D Offline
                  doktornotor Banned
                  last edited by

                  @chaycock:

                  I was looking around the Status->System Log->Firewall log and noticed that you can have the system format the message in a much easier to read format for display.

                  I filed a bug finally. Since, this is an issue ~95% of threads here where firewall logs are required for debugging issues. https://redmine.pfsense.org/issues/7323

                  1 Reply Last reply Reply Quote 0
                  • C Offline
                    chaycock
                    last edited by

                    Right, I agree, however, what I am asking is if there is a way to have this nicely formatted view sent via syslog instead of the raw view that currently gets sent.  I'm not really using the GUI to look at the logs, I use syslog, so I am interested in what is showing up there.

                    1 Reply Last reply Reply Quote 0
                    • jimpJ Offline
                      jimp Rebel Alliance Developer Netgate
                      last edited by

                      @chaycock:

                      Right, I agree, however, what I am asking is if there is a way to have this nicely formatted view sent via syslog instead of the raw view that currently gets sent.  I'm not really using the GUI to look at the logs, I use syslog, so I am interested in what is showing up there.

                      There isn't any way to have it send the formatted output via syslog. The raw output is what goes in syslog and then the GUI parses that into something more readable.

                      You might be able to lift the parsing code and adapt it for whatever you're using to view the logs on your syslog server.

                      @doktornotor:

                      I filed a bug finally. Since, this is an issue ~95% of threads here where firewall logs are required for debugging issues. https://redmine.pfsense.org/issues/7323

                      Since the hardware that was holding us back on that won't be supported on 2.4 (I'm looking at you, ALIX…) that can definitely be revisited. I'll have to see how it does on SG-1000 but it's likely acceptable there. I had initially insisted that option default to off because it was horribly slow on ALIX at the time it was introduced.

                      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                      Need help fast? Netgate Global Support!

                      Do not Chat/PM for help!

                      1 Reply Last reply Reply Quote 0
                      • C Offline
                        chaycock
                        last edited by

                        There isn't any way to have it send the formatted output via syslog. The raw output is what goes in syslog and then the GUI parses that into something more readable.

                        I was afraid of that, but thanks for letting me know.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.