Filebeat and clog (Circular Logging) format
-
I need a way to collect pfsense logs securely over the internet. Internally, pfsense is simply sending syslog to an internal logstash server. However, for remote sites syslog is not feasible.
I managed to get filebeat installed and working on pfsense. The problem is that filebeat can't work with clog files. Is there anyway to have pfsense use a normal, linear log with log rotation? I guess my only other option is to setup a site to site VPN and continue using syslog protocol?
-
Install the syslog-ng package and use it instead, and then you can have more control over what happens with the logs.
-
Fantastic workaround! Thanks for the idea.