Parse pfSense/OPNSense logs using Logstash, GeoIP tag entities, add additional context to logs, then send to Azure Sentinel for analysis.
-
Updated
Feb 28, 2022
Parse pfSense/OPNSense logs using Logstash, GeoIP tag entities, add additional context to logs, then send to Azure Sentinel for analysis.
📨 sql based firewall event logging via nflog netlink and ulogd2 userspace daemon. improved sql scheme for space efficient storage. multi-host log aggregation using dedicated sql-users.
Misc. scripts for Windows Defender Firewall
Add a description, image, and links to the firewall-logs topic page so that developers can more easily learn about it.
To associate your repository with the firewall-logs topic, visit your repo's landing page and select "manage topics."