<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with log reception using syslog PFSENSE and splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Problem-with-log-reception-using-syslog-PFSENSE-and-splunk/m-p/471031#M80972</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I'm new on reddit and I'd like a little help, I will try to be the clearest as possible.&lt;/P&gt;

&lt;P&gt;I have 2 Pfsense 2.4.5 (1 PFWAN and 1 PFLAN) And I want to receive all the syslogs logs from these 2 fw on my splunk on my LAN.&lt;/P&gt;

&lt;P&gt;My architecture is the following :&lt;BR /&gt;
-PFWAN:&lt;BR /&gt;
Wan interface : Internet address(let's say 99.99.99.99 to simplify)&lt;BR /&gt;
Lan interface : 10.10.1.2&lt;/P&gt;

&lt;P&gt;-PFLAN :&lt;BR /&gt;
Wan interface : 10.10.1.1&lt;BR /&gt;
Lan interface 10.10.10.1&lt;/P&gt;

&lt;P&gt;-My splunk on 10.10.10.30&lt;/P&gt;

&lt;P&gt;On my 2 pfsense I activated the syslog remote to my server 10.10.10.30 (I activated listening on my splunk).&lt;BR /&gt;
I currently receive perfectly the logs from my PFLAN but I have some problem to receive the logs from my PFWAN.Indeed, my firewall logs from external (like src=66.66.66.66 dst=99.99.99.99 port=445) come perfectly to my WAN interface of my PFLAN.&lt;BR /&gt;
But after that, even if the rules is allowed, the splunk doesn't receive this logs. Instead, I just have the logs src=10.10.1.2 dst=10.10.1.1 port=514.&lt;BR /&gt;
When I listen packets on 10.10.1.2 I can see the logs from external.&lt;BR /&gt;
When I listen packets on 10.10.10.1 I just have logs src=10.10.1.2 dst=10.10.1.1 port=514 and can't see the logs from external anymore.&lt;/P&gt;

&lt;P&gt;I tried to change the port to 5514 it did the same things. Could anyone help me on this topic please?&lt;/P&gt;

&lt;P&gt;Thanking you in advance,&lt;/P&gt;</description>
    <pubDate>Fri, 10 Apr 2020 16:35:40 GMT</pubDate>
    <dc:creator>albertdu93</dc:creator>
    <dc:date>2020-04-10T16:35:40Z</dc:date>
    <item>
      <title>Problem with log reception using syslog PFSENSE and splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Problem-with-log-reception-using-syslog-PFSENSE-and-splunk/m-p/471031#M80972</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I'm new on reddit and I'd like a little help, I will try to be the clearest as possible.&lt;/P&gt;

&lt;P&gt;I have 2 Pfsense 2.4.5 (1 PFWAN and 1 PFLAN) And I want to receive all the syslogs logs from these 2 fw on my splunk on my LAN.&lt;/P&gt;

&lt;P&gt;My architecture is the following :&lt;BR /&gt;
-PFWAN:&lt;BR /&gt;
Wan interface : Internet address(let's say 99.99.99.99 to simplify)&lt;BR /&gt;
Lan interface : 10.10.1.2&lt;/P&gt;

&lt;P&gt;-PFLAN :&lt;BR /&gt;
Wan interface : 10.10.1.1&lt;BR /&gt;
Lan interface 10.10.10.1&lt;/P&gt;

&lt;P&gt;-My splunk on 10.10.10.30&lt;/P&gt;

&lt;P&gt;On my 2 pfsense I activated the syslog remote to my server 10.10.10.30 (I activated listening on my splunk).&lt;BR /&gt;
I currently receive perfectly the logs from my PFLAN but I have some problem to receive the logs from my PFWAN.Indeed, my firewall logs from external (like src=66.66.66.66 dst=99.99.99.99 port=445) come perfectly to my WAN interface of my PFLAN.&lt;BR /&gt;
But after that, even if the rules is allowed, the splunk doesn't receive this logs. Instead, I just have the logs src=10.10.1.2 dst=10.10.1.1 port=514.&lt;BR /&gt;
When I listen packets on 10.10.1.2 I can see the logs from external.&lt;BR /&gt;
When I listen packets on 10.10.10.1 I just have logs src=10.10.1.2 dst=10.10.1.1 port=514 and can't see the logs from external anymore.&lt;/P&gt;

&lt;P&gt;I tried to change the port to 5514 it did the same things. Could anyone help me on this topic please?&lt;/P&gt;

&lt;P&gt;Thanking you in advance,&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2020 16:35:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Problem-with-log-reception-using-syslog-PFSENSE-and-splunk/m-p/471031#M80972</guid>
      <dc:creator>albertdu93</dc:creator>
      <dc:date>2020-04-10T16:35:40Z</dc:date>
    </item>
  </channel>
</rss>

