Pfsense extractor for Graylog

Pfsense extractor


View on Github
Open Issues

This is a set of extractors for use within Graylog, to parse the output of Pfsense filter logs.


Pfsense 2.6.0-RELEASE

  • Select Log Message Format to “syslog (RFC 5424, with RFC 3339 microsecond-precision timestamps)”
  • Set Remote log servers
  • check Remote Syslog Content

Graylog 4.2.7

System/Input => Syslog UDP:
  • Set store_full_message: true