OPNsense Forum

English Forums => 24.7, 24.10 Series => Topic started by: julsssark on November 09, 2024, 07:52:01 PM

Title: PSA: Graylog now has built-in support for OPNsense log parsing
Post by: julsssark on November 09, 2024, 07:52:01 PM
The latest version of Graylog now includes support for OPNsense log parsing. No need to maintain custom code for parsing and best of all it is available in the Open community version: https://go2docs.graylog.org/illuminate-current/what_is_illuminate/graylog_illuminate.html (https://go2docs.graylog.org/illuminate-current/what_is_illuminate/graylog_illuminate.html)

The only downside I've found is that it is labeled as "pfsense"  :)
Title: Re: PSA: Graylog now has built-in support for OPNsense log parsing
Post by: _tribal_ on November 09, 2024, 08:59:44 PM
Good news 8)
Title: Re: PSA: Graylog now has built-in support for OPNsense log parsing
Post by: Rolfieo on January 05, 2025, 05:38:08 PM
Quote from: julsssark on November 09, 2024, 07:52:01 PMThe latest version of Graylog now includes support for OPNsense log parsing. No need to maintain custom code for parsing and best of all it is available in the Open community version: https://go2docs.graylog.org/illuminate-current/what_is_illuminate/graylog_illuminate.html (https://go2docs.graylog.org/illuminate-current/what_is_illuminate/graylog_illuminate.html)

The only downside I've found is that it is labeled as "pfsense"  :)
are you sure its avaiable in the opensource version of graylog? Was what I can find, you need for illuminate the Enterprise version of Graylog.

Requirement(s)
Supported versions include Sense CE edition 2.6 and OPNsense 23.1.
Graylog server with a valid Enterprise license running Graylog 5.0.3+.
(https://go2docs.graylog.org/illuminate-current/content_packs/pfsense_firewall_security_content_pack.htm)
Title: Re: PSA: Graylog now has built-in support for OPNsense log parsing
Post by: julsssark on January 27, 2025, 02:46:36 AM
See the link from my original post and note: Hint: Graylog Open users must first upgrade their Graylog 6.1+ instance to include the Enterprise plugin before being able to install the Illuminate content hub.