I’d like to ingest Zeek logs from my PFSense. I found this content pack (BRO/Zeek IDS Logs) however it is expecting logs to be sent via RSyslog. the problem is, PFsense Zeek doesn’t have RSyslog by default.
Is there a way for Graylog to ingest the Zeek JSON files directly? If not, has anyone configure RSyslog on PFSense to send logs to Graylog?
i think PFsense syslog logs are different from Zeek. Zeek runs as a separate package within PFsense. My pfsense logs are getting ingested into Graylog via syslog, but Zeek logs are not in there.
Plain/Raw still only had network transfer options (binds to a port, etc). i just want to ingest json files.