Open cmithelpdesk opened 3 years ago
Try updating to the latest pfsense version if you can. Then make sure your time zones all match.
Hey @cmithelpdesk
This will be because your logs are set to syslog (rfc 5424) in pfsense
Change this to BSD (rfc 3164).
you will also need to revert any changes you made to the stream rules in graylog.
Regards Corey
Hey @cmithelpdesk
This will be because your logs are set to syslog (rfc 5424) in pfsense
Change this to BSD (rfc 3164).
you will also need to revert any changes you made to the stream rules in graylog.
Regards Corey
Does not seem to be correct since input takes Syslog UDP.
@cmithelpdesk, just make sure your PFsenseExtractor is set to Always try to extract.
Look like the Graylog extractor not working properly as the stream search doesn't have source and dest IP details. Refer to attached. My PFsense version 2.5.1 Any workaround available