Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfBlocker log format

    Scheduled Pinned Locked Moved pfSense Packages
    4 Posts 3 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      browner87
      last edited by

      Hi All,

      I have pfBlocker 1.0.2 on pfSense 2.1.5 (haven't made the 2.2 upgrade yet). I also recently started exporting my logs to a server running ELSA. However I've noticed that the blocked packet logs are rather useless (see screenshot). They state a rule number that was blocked, but no text. So I still have to go to my pf page to check what happened.

      SO, does anyone know if the new version of pfBlocker adds more useful logs with text strings? And if not, would it be possible to somehow make the logging format customizeable? A hack on my end or a feature request?
      Untitled.png
      Untitled.png_thumb

      1 Reply Last reply Reply Quote 0
      • D
        doktornotor Banned
        last edited by

        pfBlocker does not log anything. It creates firewall rules. Logging and its format is core pf. And no, there is no decription text in pfSense 2.2.x either. If you want description, stop using raw logs.

        1 Reply Last reply Reply Quote 0
        • BBcan177B
          BBcan177 Moderator
          last edited by

          Yes unfortunately, pfSense Syslogs do not contain the "Description" field in its output. I know that user "fearnothing" has written a parser (pfsense 2.2) for ELSA. Its available here:

          https://groups.google.com/forum/#!topic/security-onion/P4oALAvH-Ek

          "Experience is something you don't get until just after you need it."

          Website: http://pfBlockerNG.com
          Twitter: @BBcan177  #pfBlockerNG
          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

          1 Reply Last reply Reply Quote 0
          • B
            browner87
            last edited by

            Thank you BBcan! I'll look into that this weekend. I appreciate the helpful answer :)

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.