Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Graylog Pfsesne 2.5.1extractor not working properly #59

Open
cmithelpdesk opened this issue Aug 24, 2021 · 3 comments
Open

Graylog Pfsesne 2.5.1extractor not working properly #59

cmithelpdesk opened this issue Aug 24, 2021 · 3 comments

Comments

@cmithelpdesk
Copy link

Look like the Graylog extractor not working properly as the stream search doesn't have source and dest IP details. Refer to attached. My PFsense version 2.5.1 Any workaround available

graylog

@bioscopic
Copy link

Try updating to the latest pfsense version if you can. Then make sure your time zones all match.

@fatal-bundy
Copy link

Hey @cmithelpdesk

This will be because your logs are set to syslog (rfc 5424) in pfsense

Change this to BSD (rfc 3164).

you will also need to revert any changes you made to the stream rules in graylog.

Regards
Corey

@N00BIER
Copy link

N00BIER commented Feb 1, 2023

Hey @cmithelpdesk

This will be because your logs are set to syslog (rfc 5424) in pfsense

Change this to BSD (rfc 3164).

you will also need to revert any changes you made to the stream rules in graylog.

Regards Corey

Does not seem to be correct since input takes Syslog UDP.

@cmithelpdesk, just make sure your PFsenseExtractor is set to Always try to extract.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants