Firewall Live View Filtering Issue

Started by mooh, October 07, 2025, 12:33:41 PM

Previous topic - Next topic
At one of my sites, there's heavy use of network segmentation. Firewall groups keep the rules in check. In such a scenario, monitoring a group of interfaces can be extremely helpful. The interfaces within a group have already been named in a consistent way, i.e. they all share a common prefix.

Unfortunately, in Firewall: Log Files: Live View, selecting "interface contains" brings up the same menu list as "interface is", i.e. it is not possible to select multiple interfaces by matching their names as partial strings nor is it possible to select a firewall group.

The work-around is to create a composite filtering template, joining the individual results. Such a template however requires adjustment every time there is a change to a group of interfaces, but there is no obvious connection between them, making maintenance hard.

So my proposal is to either make "interface contains" a string match or allow firewall groups to be matched. At the very least, remove "contains" if it yields the same result as "is".