Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

https://devopstales.github.io/linux/graylog4-pfsense/ #9

Open
utterances-bot opened this issue Mar 24, 2022 · 6 comments
Open

https://devopstales.github.io/linux/graylog4-pfsense/ #9

utterances-bot opened this issue Mar 24, 2022 · 6 comments

Comments

@utterances-bot
Copy link

Analyzing PFsense logs in Graylog4 - devopstales

https://devopstales.github.io/linux/graylog4-pfsense/

Copy link

You lost me at

"In Cerebro we stand on top of the pfsense index and unfold the options and select delete index."

Does that not remove all the work we just did ?!?

@devopstales
Copy link
Owner

Hi @jchisholm59

We modified the template for the index. So we need to delete the index so it can be create with the new template at elasticsearch restart.

Copy link

NasKar2 commented May 7, 2022

Thanks for this document. I've been trying for 1 wk to get this working based on old you tube videos with older versions of the software. I'm now on Graylog 4.2 and Elasticsearch 7.10.2. Firewall was preventing any input initially but that is now fixed. I believe I'm getting close but don't understand why all the graphs are not populating. Any thoughts on what to check? https://imgur.com/a/MzA4wI4

Copy link
Owner

Hi @NasKar2. It is a tipicle problem with the timezone. There is a part at the Import contantpack where I configure to convert the date time in my case to Europe\Budapest.

Copy link

NasKar2 commented May 9, 2022

Thanks for the reply. The only thing I found is in pipeline/timestamp_pfsense_for_grafana. I changed it to America/New_York from your Europe/Budapest. Is there another time zone to change?

Copy link

NasKar2 commented May 12, 2022

Looks like I got most of the graphs working but editing the graph to use real_timestamp. Not sure what the correct settings are for "Top ip Block by All"

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants