Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
19.7 Legacy Series
»
Central logging with new syslog-ng targets
« previous
next »
Print
Pages: [
1
]
Author
Topic: Central logging with new syslog-ng targets (Read 4328 times)
banym
Sr. Member
Posts: 468
Karma: 31
Free Human Being, FreeBSD, Linux and Mac nerd
Central logging with new syslog-ng targets
«
on:
August 16, 2019, 02:13:36 pm »
Are there some best practices how to implement central loggin with multiple firewalls using new syslog-ng?
I plan to setup a graylog instance for all loggs to be collected.
Are the loggs tagged with the hostnames of the machines so I can point multiple firewalls to one log-server and still be able to review them by hostname?
If I have a HA-Cluster how are the loggs processed from both machines? Do they need to be configured by machine or is thet loggin switched as the secondary becommes active?
Regards,
Dominik
Logged
Twitter: banym
Mastodon: banym@bsd.network
Blog:
https://www.banym.de
abraxxa
Jr. Member
Posts: 67
Karma: 7
Re: Central logging with new syslog-ng targets
«
Reply #1 on:
August 16, 2019, 08:28:33 pm »
syslog already includes the source host(name) in each log message, just read RFC3164 and RFC5424.
The is a Logstash plugin for parsing the firewall logs by Fabian:
https://github.com/fabianfrz/logstash-filter-opnsensefilter
Logged
banym
Sr. Member
Posts: 468
Karma: 31
Free Human Being, FreeBSD, Linux and Mac nerd
Re: Central logging with new syslog-ng targets
«
Reply #2 on:
August 16, 2019, 09:10:27 pm »
Well o.k I do have the hostname in source but thats not the FQDN only the hostname.
I combine it in my filters with the IP so I can identify the logs for now for each host.
Since I have multible firewalls named fw1 for example only the FQDN would differ.
For now it works to seperate the logs. Will check how the HA-Cluster the next days.
Thanks for the references to the RFCS.
Regards,
Dominik
Logged
Twitter: banym
Mastodon: banym@bsd.network
Blog:
https://www.banym.de
abraxxa
Jr. Member
Posts: 67
Karma: 7
Re: Central logging with new syslog-ng targets
«
Reply #3 on:
August 29, 2019, 09:10:40 pm »
The 19.7.3 release notes mention that the fqdn is now sent.
Naming firewalls differently would still by my preferred option.
Logged
banym
Sr. Member
Posts: 468
Karma: 31
Free Human Being, FreeBSD, Linux and Mac nerd
Re: Central logging with new syslog-ng targets
«
Reply #4 on:
August 30, 2019, 09:27:36 am »
Thank you for the hint. Saw it already but had no time to start updating on of the firewalls to verify it is what I need.
Logged
Twitter: banym
Mastodon: banym@bsd.network
Blog:
https://www.banym.de
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
19.7 Legacy Series
»
Central logging with new syslog-ng targets