<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Internet activity - saving events]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I am a beginner in pfsensie and so I have a question. Basic.</p>
<p dir="auto">I'm looking for functionality or possibilities how to solve this problem. I need to collect such as Web logs - information such ip local computer that connects to an external ip - the date and time. In short, who visited the ip and when. I have these logs archived and kept for two years. I was looking for a solution in search engine and descriptions Packages but nothing concrete is not found. Is this a big problem in pfsensie?<br />
Or archive Internet activity, and how you resolved it?</p>
<p dir="auto">adminkg</p>
<p dir="auto">Sorry for my english</p>
]]></description><link>https://forum.netgate.com/topic/28615/internet-activity-saving-events</link><generator>RSS for Node</generator><lastBuildDate>Mon, 14 Sep 2026 21:19:12 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/28615.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 06 Dec 2010 14:48:22 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Internet activity - saving events on Tue, 07 Dec 2010 01:41:57 GMT]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">The time is in unix format. And that be so, as I understand it.</p>
<p dir="auto">Log to another physical server. How this can be done eg on Windows server? If there is a possibility.</p>
<p dir="auto">In Proxy server: General settings &gt;&gt; Custom Options I have:</p>
<pre><code>redirect_program /usr/local/bin/squidGuard -c /usr/local/etc/squidGuard/squidGuard.conf;redirector_bypass on;redirect_children 3
</code></pre>
<p dir="auto">What is this?</p>
<p dir="auto">Thank you for your reply.</p>
<p dir="auto">adminkg</p>
]]></description><link>https://forum.netgate.com/post/255458</link><guid isPermaLink="true">https://forum.netgate.com/post/255458</guid><dc:creator><![CDATA[[[global:guest]]]]></dc:creator><pubDate>Tue, 07 Dec 2010 01:41:57 GMT</pubDate></item><item><title><![CDATA[Reply to Internet activity - saving events on Mon, 06 Dec 2010 23:46:10 GMT]]></title><description><![CDATA[<p dir="auto">The time is in unix format…here is a converter:<br />
<a href="http://www.onlineconversion.com/unix_time.htm" target="_blank" rel="noopener noreferrer nofollow ugc">http://www.onlineconversion.com/unix_time.htm</a></p>
<p dir="auto">Yes, you can setup log rotation.  Yes, you can have the server log to another physical server.</p>
]]></description><link>https://forum.netgate.com/post/255450</link><guid isPermaLink="true">https://forum.netgate.com/post/255450</guid><dc:creator><![CDATA[mhab12]]></dc:creator><pubDate>Mon, 06 Dec 2010 23:46:10 GMT</pubDate></item><item><title><![CDATA[Reply to Internet activity - saving events on Mon, 06 Dec 2010 18:14:44 GMT]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">Thank you very much!</p>
<p dir="auto">I attached a sample from my Squid's access.log file from /var/squid/log/</p>
<pre><code>
1291656367.155 179583 10.30.30.112 TCP_MISS/504 1339 GET http://earthquake.usgs.gov/eqcenter/catalogs/eqs7day-M2.5.xml - DIRECT/10.30.30.2 text/html
1291656406.239  22076 10.30.30.112 TCP_MISS/000 0 GET http://finance.yahoo.com/q? - DIRECT/10.30.30.2 -
1291656406.239   4193 10.30.30.112 TCP_MISS/000 0 POST http://safebrowsing.clients.google.com/safebrowsing/downloads? - DIRECT/10.30.30.2 - 
</code></pre>
<p dir="auto">What is the date/time stamp? How to figure it out?</p>
<p dir="auto">Is this file in any way configured for the size of the time? Can you make it automatically a rip on another server. It has a rotation?</p>
<p dir="auto">adminkg</p>
]]></description><link>https://forum.netgate.com/post/255382</link><guid isPermaLink="true">https://forum.netgate.com/post/255382</guid><dc:creator><![CDATA[[[global:guest]]]]></dc:creator><pubDate>Mon, 06 Dec 2010 18:14:44 GMT</pubDate></item><item><title><![CDATA[Reply to Internet activity - saving events on Mon, 06 Dec 2010 15:40:36 GMT]]></title><description><![CDATA[<p dir="auto">The squid package will log all http traffic including destination, source, and date/time stamp.  There are also packages like lightSquid that can parse the logs into more visually appealing reports with graphs etc.  I attached a sample from Squid's access.log file so you can decide if it fits your needs:</p>
<pre><code>1230806674.821    108 10.21.1.200 TCP_MISS/200 417 HEAD http://download.windowsupdate.com/v8/windowsupdate/redir/muv3wuredir.cab? - DIRECT/65.54.87.57 application/octet-stream
1230806674.939     41 10.21.1.200 TCP_MISS/200 405 HEAD http://update.microsoft.com/v8/microsoftupdate/redir/MUAuth.cab? - DIRECT/65.55.25.93 application/octet-stream
1230806678.185     37 10.21.1.200 TCP_MISS/200 415 HEAD http://download.windowsupdate.com/v8/microsoftupdate/redir/muv3muredir.cab? - DIRECT/65.54.87.59 application/octet-stream
1230806679.883     36 10.21.1.200 TCP_REFRESH_HIT/200 8143 GET http://download.windowsupdate.com/msdownload/update/software/dflt/2008/11/1891918_f90a43e2e22893857f7c1d3228e2d01ee45bf0be.cab - DIRECT/65.54.87.59 application/octet-stream
1230806679.936     53 10.21.1.200 TCP_REFRESH_HIT/200 8143 GET http://download.windowsupdate.com/msdownload/update/software/dflt/2008/11/1891920_e7f6c3f19a0f3e20253f14efaa7aeb7a52be1936.cab - DIRECT/65.54.87.57 application/octet-stream
</code></pre>
]]></description><link>https://forum.netgate.com/post/255359</link><guid isPermaLink="true">https://forum.netgate.com/post/255359</guid><dc:creator><![CDATA[mhab12]]></dc:creator><pubDate>Mon, 06 Dec 2010 15:40:36 GMT</pubDate></item></channel></rss>