# Extractors for pfSense

**URL:** <https://community.graylog.org/t/extractors-for-pfsense/1640>\
**Category:** Graylog Add-ons\
**Created:** [July 4, 2017, 10:47am UTC](https://community.graylog.org/t/extractors-for-pfsense/1640 "2017-07-04T10:47:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![heisenberg1977](https://avatars.discourse-cdn.com/v4/letter/h/df705f/32.png) [@heisenberg1977](https://community.graylog.org/u/heisenberg1977)\
**Post date:** [July 4, 2017, 10:47am UTC](https://community.graylog.org/t/extractors-for-pfsense/1640/1 "2017-07-04T10:47:11Z")

</div>

Hi,

New to Graylog. I configured the VM and started sending my pfSense logs. I then found a link to the extractors in the Marketplace, but they do not appear to be working.

> **[Hobadee/Graylog\_Extractors\_pfSense](https://github.com/Hobadee/Graylog_Extractors_pfSense)**
>
> My Graylog Extractors for pfSense filterlogs. Contribute to Hobadee/Graylog\_Extractors\_pfSense development by creating an account on GitHub.

I’m running pfSense v.2.3.4 and Graylog v.2.2.3

I see some links to other extractors when doing a Google search, but only the link above exists in the Marketplace. Looking for tips to get this working.

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [July 4, 2017, 4:01pm UTC](https://community.graylog.org/t/extractors-for-pfsense/1640/2 "2017-07-04T16:01:03Z")

</div>

did you checked the issues for that?

> **[Hobadee/Graylog\_Extractors\_pfSense](https://github.com/Hobadee/Graylog_Extractors_pfSense/issues)**
>
> My Graylog Extractors for pfSense filterlogs. Contribute to Hobadee/Graylog\_Extractors\_pfSense development by creating an account on GitHub.

---

<div class="post-metadata">

**Author:** ![heisenberg1977](https://avatars.discourse-cdn.com/v4/letter/h/df705f/32.png) [@heisenberg1977](https://community.graylog.org/u/heisenberg1977)\
**Post date:** [July 5, 2017, 4:58am UTC](https://community.graylog.org/t/extractors-for-pfsense/1640/3 "2017-07-05T04:58:17Z")

</div>

I’ll have to take a further look. After filtering to view all logs from source **filterlog:** in real time, I can see that some are being parsed correctly and some are not.

So far Graylog looks promising as a syslog solution for pfSense. I need to take the time to read the documentation more thoroughly and find some good tutorials.

---

<div class="post-metadata">

**Author:** ![heisenberg1977](https://avatars.discourse-cdn.com/v4/letter/h/df705f/32.png) [@heisenberg1977](https://community.graylog.org/u/heisenberg1977)\
**Post date:** [July 5, 2017, 11:27am UTC](https://community.graylog.org/t/extractors-for-pfsense/1640/4 "2017-07-05T11:27:54Z")

</div>

@jan - I fixed the regex used for udp to lowercase as per one of the issues and it appears to have fixed part of my problem. There are still a few events coming through that are not parsing correctly. I’ll have to take a look at those next. - Thx

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [July 19, 2017, 11:27am UTC](https://community.graylog.org/t/extractors-for-pfsense/1640/5 "2017-07-19T11:27:54Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
