Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG remote logging

    pfBlockerNG
    2
    5
    961
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      JohanÅ
      last edited by

      Hi,

      Firstly, sorry if this has been asked before but I did not find topic regarding this with search.

      I'm logging PGSense logs remotely but I noticed that eventhough I have set PFSense to send "Everything" it is not sending pfBlockerNG logs.

      Is there any way of do this?

      1 Reply Last reply Reply Quote 0
      • RonpfSR
        RonpfS
        last edited by

        @JohanÅ said in pfBlockerNG remote logging:

        I'm logging PGSense logs remotely but I noticed that eventhough I have set PFSense to send "Everything" it is not sending

        pfBlockerNG doesn't use syslog, it manage it's log files in /var/log/pfblockerNG.

        2.4.5-RELEASE-p1 (amd64)
        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

        1 Reply Last reply Reply Quote 0
        • J
          JohanÅ
          last edited by

          Hmm ok. Any idea why it is so? Isn't that way worst than using syslog?

          So does anyone have an idea what would be the best way to send the log file to remote server and then parse it with logstash? I know that Logstash is able to parse files but was wondering how to make sure that it does not log duplicates. This is more Elasticsearch topic but if someone has done this already, I would appreciate any idea.

          I was not able to find logging settings to dnsbl, I would like to limit the truncate of the logging file to 24h so I could send it every day and maybe limit the duplicates.

          RonpfSR 1 Reply Last reply Reply Quote 0
          • RonpfSR
            RonpfS @JohanÅ
            last edited by

            @JohanÅ said in pfBlockerNG remote logging:

            Hmm ok. Any idea why it is so? Isn't that way worst than using syslog?

            pfBlockerNG does a lot of processing on Firewall and DNSBL logs. This is needed for the Widget and Reports tabs.

            2.4.5-RELEASE-p1 (amd64)
            Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
            Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

            J 1 Reply Last reply Reply Quote 0
            • J
              JohanÅ @RonpfS
              last edited by

              @RonpfS

              That is understandable. Thanks for the answers. I'll try to find a way to use these logs in my need.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.