Grafana Dashboard for OPNsense and the Plugin Sensei
Configuration of the pfelk Elasticsearch Datasources :
Name : Elasticsearch-Firewall
URL : yourELKIP:9200
Index name : pfelk-firewall*
Time field name : @timestamp
Version : 7.0+
Name : Elasticsearch-Suricata
URL : yourELKIP:9200
Index name : pfelk-suricata*
Time field name : @timestamp
Version : 7.0+
Name : Elasticsearch-unbound
URL : yourELKIP:9200
Index name : pfelk-unbound*
Time field name : @timestamp
Version : 7.0+
You can use the Name you want and filter it in the dashboard your import, in the Settings -> Variables -> Elasticsearch
-> Adn modify the "Instance name filter" for exemple here for matching suricata : /.*Suricata.*/
Dashboard OPNSense :
InfluxDB : OPNSense - Firewall
ELK : Firewall - Dashboard | Firewall - Suricata | Firewall - Unbound
Configure Sensei by using external ELK (like the one you have previously install) Or you can use the internal ELK who is install during the Sensei installation. Just configure a Port translation from your administration interface or OPNsense on the port 9200 to the 127.0.0.1:9200
Link : https://opnsense.org/ OPNsense is an OSS project © Deciso B.V. 2015-2020 - All rights reserved https://www.sunnyvalley.io/sensei/ Sunny Valley Networks name and logo are trademarks of Sunny Valley Cyber Security Inc. All other brand names, product names, or trademarks belong to their respective owners.