Better logs view
-
So I have a question. At our company we use the Barracuda firewall and the logs are very clear, and you can filter them very well. My question now: Is it possible to upgrade the Pfsense logs somehow or improve them with packages so that they are clearer, and it is easier to work with them?
I don't know, maybe it's just me being so picky, but what do you think of the logs and is there a solution?
One example that fucks me up is that pfsense doesn't automatically resolve internal IPs registered on the DNS? It would also be an advantage to be able to show and hide information such as specific protocol information or similar, or to be able to set standard filters or create profiles with filters. Also, the possibility to filter for multiple ports and multiple hosts at the same time would be simply awesome and very helpful sometimes. It would also be super nice to be able to develop packages that make it possible to expand the logs. An example would be that you could display geoip information with pfblocker, or I don't know.
There are many other things I could mention, but what I want to say is: the logs are so important and can be so helpful, why does pfsense neglect them so much? Sure they are not crap, but they are not good either.
Thank you and I look forward to your feedback
By the way, this is the default log view of Barracuda Firewall, in which you have some functions mentioned above. More about the firewall logs in Barracuda here: https://campus.barracuda.com/product/cloudgenfirewall/doc/79463237/history-page/
-
ntopng, darkstath, bandwidthd probably there are other packages now that can give you a better log view, idk, personally i send everything to grafana and i let the firewall do the firewall.