<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TA-pfsense sourcetyping only catching filterlog in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-sourcetyping-only-catching-filterlog/m-p/507095#M62299</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/30898"&gt;@token2&lt;/a&gt;, I had a similar issue, and documented my solution here: &lt;A href="https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-transforms-conf-pfsense-sourcetyper-broken/m-p/507092#M62298" target="_blank"&gt;https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-transforms-conf-pfsense-sourcetyper-broken/m-p/507092#M62298&lt;/A&gt;.&amp;nbsp; Take a look and see if that helps you any.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Jul 2020 14:24:41 GMT</pubDate>
    <dc:creator>pkt_nspktr</dc:creator>
    <dc:date>2020-07-02T14:24:41Z</dc:date>
    <item>
      <title>TA-pfsense sourcetyping only catching filterlog</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-sourcetyping-only-catching-filterlog/m-p/502035#M61789</link>
      <description>&lt;P&gt;Running into an issue where TA-pfsense is only creating three sourcetypes-&lt;BR /&gt;
pfsense:filterlog&lt;BR /&gt;
pfsense:dhclient&lt;BR /&gt;
pfsense&lt;/P&gt;

&lt;P&gt;I'm not that Splunk savey.  Looking at the props and transforms, and then the data in splunk (_raw).  I'm wondering if the lack of time being in the raw log is throwing off the transforms to create sourcetype.&lt;/P&gt;

&lt;P&gt;example raw log not getting sourcetyped by the app (so ends up with sourcetype=pfsense)&lt;/P&gt;

&lt;P&gt;/index.php: User logged out for user 'admin' from: 192.168.1.151 (Local Database)&lt;/P&gt;

&lt;P&gt;OR&lt;/P&gt;

&lt;P&gt;sendmsg: Permission denied&lt;/P&gt;

&lt;P&gt;Example of raw log getting sourcetyped as pfsense:dhclient which is not addressed in the props.&lt;/P&gt;

&lt;P&gt;Mar 28 22:13:03 dhclient: FAIL&lt;/P&gt;

&lt;P&gt;Looking at the transforms' &lt;/P&gt;

&lt;P&gt;[pfsense_sourcetyper]&lt;BR /&gt;
REGEX = \w{3}\s+\d{1,2}\s\d{2}:\d{2}:\d{2}\s(?:[\w.]+\s)?(\w+)&lt;/P&gt;

&lt;P&gt;I'm assuming it gets past the time stamp, and the following is what gets grabbed as sourcetype to append to pfsense:&lt;BR /&gt;
With this assumption, the raw logs without time in the raw simply get sourcetyped pfsense.&lt;/P&gt;

&lt;P&gt;This is causing OpenVPN logs, nginx, dhcpd etc to not accurately get sourcetyped and fields extracted as they are sourcetyped simply 'pfsense'.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Mar 2020 05:19:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-sourcetyping-only-catching-filterlog/m-p/502035#M61789</guid>
      <dc:creator>token2</dc:creator>
      <dc:date>2020-03-29T05:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: TA-pfsense sourcetyping only catching filterlog</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-sourcetyping-only-catching-filterlog/m-p/507095#M62299</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/30898"&gt;@token2&lt;/a&gt;, I had a similar issue, and documented my solution here: &lt;A href="https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-transforms-conf-pfsense-sourcetyper-broken/m-p/507092#M62298" target="_blank"&gt;https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-transforms-conf-pfsense-sourcetyper-broken/m-p/507092#M62298&lt;/A&gt;.&amp;nbsp; Take a look and see if that helps you any.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 14:24:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-sourcetyping-only-catching-filterlog/m-p/507095#M62299</guid>
      <dc:creator>pkt_nspktr</dc:creator>
      <dc:date>2020-07-02T14:24:41Z</dc:date>
    </item>
  </channel>
</rss>

