-
|
Hello a3ilson, I have setted a pfelk for our old pfsense 2.4.4p3, the logs are coming in but it seems I can't see the network.name section. And as you can see below, there is no network.name The interface name is displayed. I have another pfELK for pfsense 2.5.2 and it works like a charm, is it because of the 2.4.4p3 version ? |
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 2 replies
-
|
The other pfelk working is on version 20.10 and the one I use for pfsense 2.4.4p3 is on 22.01 |
Beta Was this translation helpful? Give feedback.
-
|
@n4rkip0d - the update to version 22.01 removed the multiple listening ports and the various types (e.g. firewall-1, firewall-2 etc...). With the 20-interfaces.conf you'll need to update line 11 ( This will work with pfSense 2.5.0+ but prior versions do not contain the hostname in the remote logs. Ideally the would best solution would be for @pfsense to utilize syslog-ng rather than old/superseded formats. The solution would be to update pfSense or I can create a modified 20-interfaces.conf file for you setup. Is the pfelk instance listening for multiple pfSense logs or just one? |
Beta Was this translation helpful? Give feedback.
-
|
@n4rkip0d - use the contents below to add a new file named |
Beta Was this translation helpful? Give feedback.


@n4rkip0d - use the contents below to add a new file named
02-legacy_pfsense_fix.confand update20-interfaces.confto the latest version. Next, amend both02-legacy_pfsense_fix.confand20-interfaces.confhost.name value fromfirst.network.localto any desired name.