OPNsense Forum

Archive => 19.7 Legacy Series => Topic started by: banym on August 16, 2019, 02:13:36 PM

Title: Central logging with new syslog-ng targets
Post by: banym on August 16, 2019, 02:13:36 PM
Are there some best practices how to implement central loggin with multiple firewalls using new syslog-ng?

I plan to setup a graylog instance for all loggs to be collected.

Regards,

Dominik
Title: Re: Central logging with new syslog-ng targets
Post by: abraxxa on August 16, 2019, 08:28:33 PM
syslog already includes the source host(name) in each log message, just read RFC3164 and RFC5424.
The is a Logstash plugin for parsing the firewall logs by Fabian: https://github.com/fabianfrz/logstash-filter-opnsensefilter
Title: Re: Central logging with new syslog-ng targets
Post by: banym on August 16, 2019, 09:10:27 PM
Well o.k I do have the hostname in source but thats not the FQDN only the hostname.
I combine it in my filters with the IP so I can identify the logs for now for each host.

Since I have multible firewalls named fw1 for example only the FQDN would differ.

For now it works to seperate the logs. Will check how the HA-Cluster the next days.

Thanks for the references to the RFCS.

Regards,

Dominik
Title: Re: Central logging with new syslog-ng targets
Post by: abraxxa on August 29, 2019, 09:10:40 PM
The 19.7.3 release notes mention that the fqdn is now sent.
Naming firewalls differently would still by my preferred option.
Title: Re: Central logging with new syslog-ng targets
Post by: banym on August 30, 2019, 09:27:36 AM
Thank you for the hint. Saw it already but had no time to start updating on of the firewalls to verify it is what I need.  :)