Syslog parser for Microsoft Defender for Cloud Apps Discovery
-
I am trying to make use of the Microsoft Defender for Cloud Apps Discovery, and I need to collect the logs from my Netgate SG-7100. I have it sending now to a kiwi syslog server on-prem.
The format that Netgate uses doesn't seem to conform to any of the presets available, I think I need to make a custom log parser. I am a bit lost at this step. Can anyone provide a bit of guidance?
-
You can change the log format in 2.6/22.01 to use RFC 5424 instead:
https://docs.netgate.com/pfsense/en/latest/monitoring/logs/settings.html#global-log-settingsThe filter log format is described here:
https://docs.netgate.com/pfsense/en/latest/monitoring/logs/raw-filter-format.htmlSteve
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.