opc40772 / pfsense-graylog

Pfsense Logs Parsed by Graylog
GNU General Public License v3.0
82 stars 117 forks source link

Believe this is now broken in Graylog 3.x #14

Open JSylvia007 opened 5 years ago

JSylvia007 commented 5 years ago

This is now broken due to changes in Graylog 3.x (and a critical support package dropping support for underscores).

https://github.com/Graylog2/graylog2-server/issues/5704 https://github.com/thekrakken/java-grok/issues/108 https://community.graylog.org/t/upgrade-of-graylog-from-2-5-x-to-3-x-results-in/9368

Berzerker commented 5 years ago

Agree, tried to get this working with 3.0, but I got stuck a few times. An update for 3.0 would be great.

JSylvia007 commented 5 years ago

I think it will begin working again when graylog 3.0.1 is released.

devzwf commented 5 years ago

with 3.0.1 released , is this work again ?

JSylvia007 commented 5 years ago

with 3.0.1 released , is this work again ?

Yup! I just updated without any changes and it starting working again.

devzwf commented 5 years ago

when trying to install content pack i have :

Error
Installing content pack failed with status: Error: cannot POST http://<IP Removed>:9600/api/system/content_packs/1057ded6-9d12-4c8e-8c0c-789a19ff61d2/0/installations (500). Could not install content pack with ID: 1057ded6-9d12-4c8e-8c0c-789a19ff61d2
JSylvia007 commented 5 years ago

Unfortunately, I needed to manually hack it to get it installed. Once it is installed, it works, but there were multiple changes that I needed to make. Unfortunately, it varies for each person's install of Graylog/Grafana, etc.

devzwf commented 5 years ago

where should i start ? :) i will check the log

JSylvia007 commented 5 years ago

Good Luck my friend. I believe I looked at the graylog server log and started to fix the issues one-by-one in the JSON file and then attempted a re-import. I did this for EACH issue I came across. I remember it took me a whole weekend to get this sorted out and installed.

devzwf commented 5 years ago

Thanks i goona try and start with the lookup one , or i will install by 2.5 and them update we will see, will be fun :)

devzwf commented 5 years ago

just want to report back I was able to make this work with graylog 3.0.1 + grafana 6.1.1+ elasticsearch 6.7.1 lots of poking and error try.... thanks to snapshot :)

I am not fully statisfied yet of the result (geoip still flaky) , still need some polish but it is working

mauroprojetos commented 5 years ago

Could someone share and file to work with graylog 3.1?

derekslenk commented 5 years ago

Could someone share and file to work with graylog 3.1?

Or point to the log files to look at?

devzwf commented 5 years ago

I will try to write the step i used (not easy , like i said was a lot of poking but i will give the basic direction)

derekslenk commented 5 years ago

I will try to write the step i used (not easy , like i said was a lot of poking but i will give the basic direction)

Many thanks

CluelessTechnologist commented 5 years ago

I will try to write the step i used (not easy , like i said was a lot of poking but i will give the basic direction)

Sorry to bother you but did you ever finish this updated step by step?

CluelessTechnologist commented 5 years ago

Can someone up the updated json file?

ghost commented 5 years ago

Also trying to get this to work. @devzwf any pointers would be awesome!

devopstales commented 5 years ago

I created an updated version of this content pack for graylog3. You can find the instrucions HERE @devzwf @mauroprojetos @derekslenk @CluelessTechnologist @frogger72

GraysonPeddie commented 4 years ago

Please pardon me for bringing up this old thread but I cannot install pfSense content pack in Graylog 3 and I tried to click in the link for an updated version of the content pack but I got a 404 not found.