Getting Data In

How to troubleshoot why my PFsense logs are not getting indexed correctly and logs stop at 11:59:59?

gosports
New Member

I have PFsense sending logs to Splunk running on Ubuntu 14.04 server. When I check pfsense internal logs, everything works fine, but when I go to Splunk, it shows me output that's not in pfsense and the date is far off.

11/5/10 11:59:59.000 PM  Nov  4 23:59:59 10.0.0.10 Nov  5 05:00:00 /usr/sbin/cron[77798]: (root) CMD (/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 sshlockout)

host = 10.0.0.10
source = udp:514
sourcetype = pfsense

When I check the count on the main page in Splunk, I see the right count and time, but when I click on the host, that's what I see. I tried to restart Splunk, but didn't help.
Please, suggest what could be the issue. Thanks

0 Karma

jterry
Splunk Employee
Splunk Employee

i'm not familiar w/PFsense & the log format it emits but it sounds like the fields are not being recognize/parsed correctly by Splunk.
In the absence of a TA that might supply the needed sourcetype definition, you may have to define one.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...