Skip to content

pfSense

Chronicle supports ingesting pfSense telemetry logs to help visualize network traffic for and surrounding alerts.

Chronicle Data Types

  • PFSENSE

Configuration

Reference: https://docs.netgate.com/pfsense/en/latest/monitoring/copying-logs-to-a-remote-host-with-syslog.html

  1. Click Status > System Logs
  2. Click the Settings tab
  3. Check Enable syslog’ing to remote syslog server
  4. Type the IP of the CYCLOPS appliance in the box next to Remote syslog server
  5. Cyderes recommends checking the boxes for all log entries to forward
  6. Click Save