Project

General

Profile

Actions

Feature #11809

closed

Provide the option of logging in CEF (Common Event Format) in addition to Syslog

Added by Justin Andrusk about 3 years ago. Updated almost 3 years ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Category:
Logging
Target version:
-
Start date:
04/16/2021
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Default

Description

When sending to remote log sources, especially those that are used as logging solutions such as logstash, Graylog, Splunk, etc.. it would be a great benefit to be able to send PFSense messages in CEF (Common Event Format) so that when they arrive the fields are already parsed instead of having to write custom parsers. Custom parsers are even harder to implement based on format differences between different types of messages.

CEF Standard: https://community.microfocus.com/t5/ArcSight-Connectors/ArcSight-Common-Event-Format-CEF-Implementation-Standard/ta-p/1645557?attachment-id=68077

Actions #2

Updated by Jim Pingle almost 3 years ago

  • Status changed from New to Rejected

Not viable for the built-in syslogd, what can be done is already possible in syslog-ng.

Actions

Also available in: Atom PDF