Snort log files to rsyslog server
-
Is there any way to configure this via the web gui? I checked status -> system logs, and also the Snort tab under Services.
-
Sure, on the INTERFACE SETTINGS tab for the Snort interface, you can choose to send logs to the system log (which is syslog). You can also configure some of the metadata tags that are attached.
So go to the INTERFACES tab in Snort, and then either double-click on the interface line in the table or click the edit icon (the little pencil) on the right side of the table row to bring up the INTERFACE SETTINGS tab.
Within pfSense you can configure the system logs to be sent to a remote syslog server, if you want to do that.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.