Re: Managing PF logs

2020-08-07 Thread Carlos Lopez
-- Cordialement, Pierre BARDOU -Message d'origine- De : owner-m...@openbsd.org De la part de Peter N. M. Hansteen Envoyé : vendredi 7 août 2020 13:10 À : misc@openbsd.org Objet : Re: Managing PF logs On Fri, Aug 07, 2020 at 10:29:32AM +, Carlos Lopez

Re: Managing PF logs

2020-08-07 Thread pierre1.bardou
t de Peter N. M. Hansteen Envoyé : vendredi 7 août 2020 13:10 À : misc@openbsd.org Objet : Re: Managing PF logs On Fri, Aug 07, 2020 at 10:29:32AM +, Carlos Lopez wrote: > Hi all, > > I am thinking about how could be the best option to inject PF logs in > Elasticsearch (or any simi

Re: Managing PF logs

2020-08-07 Thread Peter N. M. Hansteen
On Fri, Aug 07, 2020 at 10:29:32AM +, Carlos Lopez wrote: > Hi all, > > I am thinking about how could be the best option to inject PF logs in > Elasticsearch (or any similar platform). If I am not wrong, some years ago > there is an option using a shell wrapper to store all pf logs in

Re: Managing PF logs

2020-08-07 Thread Tom Smyth
pf logs are stored in Tcpdump format, so you can parse them with tcpdump before dumping them into your analysis dbs On Fri, 7 Aug 2020 at 11:36, Carlos Lopez wrote: > Hi all, > > I am thinking about how could be the best option to inject PF logs in > Elasticsearch (or any similar