<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TA-pfsense: Why are none of the fields being parsed? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/120005#M9135</link>
    <description>&lt;P&gt;Please check that the TA is installed on your search head (if you use distributed search) and that you are not searching in "Fast Mode"&lt;/P&gt;</description>
    <pubDate>Sun, 14 Feb 2016 15:20:45 GMT</pubDate>
    <dc:creator>my2ndhead</dc:creator>
    <dc:date>2016-02-14T15:20:45Z</dc:date>
    <item>
      <title>TA-pfsense: Why are none of the fields being parsed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/119991#M9121</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have installed TA-PFSense, sent the logs to the network index with sourcetype pfsense, but none of the fields are being parsed. Do I need to merge the transform.conf or props.conf with the main system or anything else?&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2015 02:10:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/119991#M9121</guid>
      <dc:creator>Epicism1</dc:creator>
      <dc:date>2015-04-01T02:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: TA-pfsense: Why are none of the fields being parsed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/119992#M9122</link>
      <description>&lt;P&gt;try this to extract fields properly&lt;/P&gt;

&lt;P&gt;&lt;A href="http://blog.basementpctech.com/2012/02/splunk-and-pfsense-what-pair.html"&gt;http://blog.basementpctech.com/2012/02/splunk-and-pfsense-what-pair.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2015 03:48:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/119992#M9122</guid>
      <dc:creator>kml_uvce</dc:creator>
      <dc:date>2015-04-01T03:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: TA-pfsense: Why are none of the fields being parsed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/119993#M9123</link>
      <description>&lt;P&gt;I appreciate your answer, but I guess I'm more trying to understand how the app is supposed to work. Should I enter the props.conf/transform.conf entries into splunk manually, or do I have to add what is in the blog on top of the app. If so, what is the point of the app.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2015 11:15:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/119993#M9123</guid>
      <dc:creator>Epicism1</dc:creator>
      <dc:date>2015-04-01T11:15:47Z</dc:date>
    </item>
    <item>
      <title>Re: TA-pfsense: Why are none of the fields being parsed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/119994#M9124</link>
      <description>&lt;P&gt;The add-on  expects the log data to initially be of sourcetype "pfsense". The add-on will then create new sourcetypes (e.g. "pfsense:filterlog")&lt;/P&gt;

&lt;P&gt;Be sure to use version 2.0.2 as there was a bug in version 2.0&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2015 10:11:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/119994#M9124</guid>
      <dc:creator>my2ndhead</dc:creator>
      <dc:date>2015-04-06T10:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: TA-pfsense: Why are none of the fields being parsed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/119995#M9125</link>
      <description>&lt;P&gt;This TA has a requirement that you are sending the syslog &lt;STRONG&gt;directly&lt;/STRONG&gt; to Splunk.  As such, you have to create a UDP listener (&lt;EM&gt;Settings &amp;gt; Data Inputs &amp;gt; UDP&lt;/EM&gt;) on a port (e.g. 5514) and then associate the appropriate sourcetype (pfsense) and index (network) for it to work out-of-box.&lt;/P&gt;

&lt;P&gt;I originally tried just sending the syslogs to a file via rsyslog and having Splunk monitor the file.  That won't work without modifying the TA.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 10:21:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/119995#M9125</guid>
      <dc:creator>pickerin</dc:creator>
      <dc:date>2015-10-20T10:21:56Z</dc:date>
    </item>
    <item>
      <title>Re: TA-pfsense: Why are none of the fields being parsed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/119996#M9126</link>
      <description>&lt;P&gt;Oh that's exactly my problem. Do you know what part I will need to modify?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 12:59:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/119996#M9126</guid>
      <dc:creator>Epicism1</dc:creator>
      <dc:date>2015-10-20T12:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: TA-pfsense: Why are none of the fields being parsed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/119997#M9127</link>
      <description>&lt;P&gt;I haven't dug into the TA to see how it's built, but I assume that since it takes a given sourcetype (pfsense) and then performs field extractions on it and creates additional sourcetypes (pfsense:logfilter, pfsense:dhcpd, pfsense:webui, etc) that you'd have to modify the TA itself rather significantly to allow it to be used on monitored files.&lt;/P&gt;

&lt;P&gt;You could reach out to the TA author and see if s/he responds.&lt;/P&gt;

&lt;P&gt;Perhaps someone else can weigh in on how to fix this, I just went ahead and created the UDP listener and it started working great.&lt;/P&gt;

&lt;P&gt;(p.s. if my answer was correct for identifying your problem, please mark it as answered)&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 13:03:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/119997#M9127</guid>
      <dc:creator>pickerin</dc:creator>
      <dc:date>2015-10-20T13:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: TA-pfsense: Why are none of the fields being parsed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/119998#M9128</link>
      <description>&lt;P&gt;I downvoted this post because this blog post is for the old format of pfsense logs. version 2.2 and above use single-line file formats. this won't work anymore.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 20:10:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/119998#M9128</guid>
      <dc:creator>nickatripp</dc:creator>
      <dc:date>2016-02-09T20:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: TA-pfsense: Why are none of the fields being parsed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/119999#M9129</link>
      <description>&lt;P&gt;I have all of these settings configured as you say, but the logs still aren't being parsed.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 20:11:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/119999#M9129</guid>
      <dc:creator>nickatripp</dc:creator>
      <dc:date>2016-02-09T20:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: TA-pfsense: Why are none of the fields being parsed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/120000#M9130</link>
      <description>&lt;P&gt;-Please be sure to have the latest TA-pfsense installed (2.0.5)&lt;BR /&gt;
-What are the sourcetypes you get?&lt;BR /&gt;
-The sourcetype pfsense will be rewritten by props.conf/transforms.conf. Check that the TA is on the right Splunk instance that running the parsing phase (refer to this document &lt;A href="http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F"&gt;http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F&lt;/A&gt;)&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 21:27:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/120000#M9130</guid>
      <dc:creator>my2ndhead</dc:creator>
      <dc:date>2016-02-09T21:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: TA-pfsense: Why are none of the fields being parsed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/120001#M9131</link>
      <description>&lt;P&gt;Hi there. I do have version 2.0.5 of TA-pfsense installed.&lt;/P&gt;

&lt;P&gt;I'm certain that TA is on the right Splunk instance as I only have one instance of Splunk. This is a brand new Splunk install, and currently I am only sending pfSense logs to it.&lt;/P&gt;

&lt;P&gt;I am receiving the log data from pfSense and those events are showing "pfsense:" as their sourcetype. They are being sent to the "network" index. (Is it necessary that they go to the network index?)&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 23:29:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/120001#M9131</guid>
      <dc:creator>nickatripp</dc:creator>
      <dc:date>2016-02-09T23:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: TA-pfsense: Why are none of the fields being parsed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/120002#M9132</link>
      <description>&lt;P&gt;I appear to be having an issue where the TA does not appear to be creating proper sourcetypes. I just see 'pfsense:'&lt;/P&gt;</description>
      <pubDate>Sat, 13 Feb 2016 03:01:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/120002#M9132</guid>
      <dc:creator>xECK29x</dc:creator>
      <dc:date>2016-02-13T03:01:39Z</dc:date>
    </item>
    <item>
      <title>Re: TA-pfsense: Why are none of the fields being parsed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/120003#M9133</link>
      <description>&lt;P&gt;I have pushed a new version to splunkbase (2.0.6) , there was a bug in the sourcetyper under default/transforms.conf.&lt;/P&gt;

&lt;P&gt;You can use whatever index you want. Just specify one that fits your environment in your inputs.conf.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Feb 2016 09:43:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/120003#M9133</guid>
      <dc:creator>my2ndhead</dc:creator>
      <dc:date>2016-02-14T09:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: TA-pfsense: Why are none of the fields being parsed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/120004#M9134</link>
      <description>&lt;P&gt;Thanks!&lt;/P&gt;

&lt;P&gt;I updated to 2.0.6 and now my firewall logs are being assigned the sourcetype of "pfsense:filterlog". So that's an improvement.&lt;/P&gt;

&lt;P&gt;However, it seems the fields within the logs still aren't being parsed. For example, my latest log line looks like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Feb 14 08:19:21 filterlog: 5,16777216,,1000000103,bge1,match,block,in,4,0xc0,,46,12426,0,none,1,icmp,1.1.1.1,2.2.2.2,unreachport,1.1.1.1,UDP,5384
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sun, 14 Feb 2016 13:23:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/120004#M9134</guid>
      <dc:creator>nickatripp</dc:creator>
      <dc:date>2016-02-14T13:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: TA-pfsense: Why are none of the fields being parsed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/120005#M9135</link>
      <description>&lt;P&gt;Please check that the TA is installed on your search head (if you use distributed search) and that you are not searching in "Fast Mode"&lt;/P&gt;</description>
      <pubDate>Sun, 14 Feb 2016 15:20:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/120005#M9135</guid>
      <dc:creator>my2ndhead</dc:creator>
      <dc:date>2016-02-14T15:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: TA-pfsense: Why are none of the fields being parsed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/120006#M9136</link>
      <description>&lt;P&gt;TA is installed on my search head. My environment is not distributed. Just a single Splunk server.&lt;/P&gt;

&lt;P&gt;I am searching in "Smart Mode".&lt;/P&gt;</description>
      <pubDate>Sun, 14 Feb 2016 19:18:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TA-pfsense-Why-are-none-of-the-fields-being-parsed/m-p/120006#M9136</guid>
      <dc:creator>nickatripp</dc:creator>
      <dc:date>2016-02-14T19:18:35Z</dc:date>
    </item>
  </channel>
</rss>

