pfSense to Azure Sentinel via Logstash #226
Replies: 9 comments 26 replies
-
@noodlemctwoodle - Thanks and greatly appreciated. This should certainly helps others with a similar setup! I also know that others are making gains on the UNRaid variant (#188). |
Beta Was this translation helpful? Give feedback.
-
@a3ilson I have a question about the
Am I right in thinking that |
Beta Was this translation helpful? Give feedback.
-
found it! The GROK pattern was adjusted to align with pfSense documentation and ECS but the 35-rules-desc.conf was not. I'll submitted a pull request...let me know if the update works. |
Beta Was this translation helpful? Give feedback.
-
Thanks, I've added the change. I'll give it 10 mins to update |
Beta Was this translation helpful? Give feedback.
-
You'll need to restart Logstash for it to take, due to the field name change, but thereafter, amending the rules database file should be sufficient as it refreshes the database every 60-seconds. |
Beta Was this translation helpful? Give feedback.
-
I added two wiki pages but the pull request didn't`t capture... I'll attach include here for inclusion to your repo. |
Beta Was this translation helpful? Give feedback.
-
@a3ilson I've fixed it :)
|
Beta Was this translation helpful? Give feedback.
-
Now I have to go Christmas food shopping before all the shops run out of food as France have shut the borders to the UK due to covid and there is mass panic that the shops will run short of stock in the run-up to Christmas...... What a chore!! :@ |
Beta Was this translation helpful? Give feedback.
-
Any though on amending the repository from pfsense-azure-sentinel to pf-azure-sentinel? The setup will work for both pfSense and OPNsense? Also I would recommend added tags to your repository aiding those searching for this capability. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
@a3ilson - I have finally reached my end goal of getting my pfSense logs to Azure Sentinel and I just wanted to show my appreciation and say thank you, because without your project it would have taken me considerably longer. I've attempted many ways to get my pfSence logs to Azure.
As you aware I really wanted to use a docker container on UnRAID, however it was causing a my server to run out of resources and at the end of the day I didnt really want to use Elastic Search or Kibana for my project as I am already using Azure Sentinel as my SIEM solution.
For anyone else that is intersted in my Azure Sentinel project you can view it on my GitHub.
Once again without the work from @a3ilson this would not be possible so thank you very much for your hard work... :D
Beta Was this translation helpful? Give feedback.
All reactions