Project

General

Profile

Feature #11809

Provide the option of logging in CEF (Common Event Format) in addition to Syslog

Added by Justin Andrusk 27 days ago. Updated 24 days ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Category:
Logging
Target version:
-
Start date:
04/16/2021
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Default

Description

When sending to remote log sources, especially those that are used as logging solutions such as logstash, Graylog, Splunk, etc.. it would be a great benefit to be able to send PFSense messages in CEF (Common Event Format) so that when they arrive the fields are already parsed instead of having to write custom parsers. Custom parsers are even harder to implement based on format differences between different types of messages.

CEF Standard: https://community.microfocus.com/t5/ArcSight-Connectors/ArcSight-Common-Event-Format-CEF-Implementation-Standard/ta-p/1645557?attachment-id=68077

History

#2 Updated by Jim Pingle 24 days ago

  • Status changed from New to Rejected

Not viable for the built-in syslogd, what can be done is already possible in syslog-ng.

Also available in: Atom PDF