Configuring Netgate pfSense to communicate with QRadar
To send syslog messages to IBM® QRadar®, the Netgate pfSense remote logging options must be configured to specify a remote log server.
Before you begin
If you want to send Snort IDS events to QRadar, ensure that the Snort package for Netgate pfSense is installed and configured. Snort is an open source network intrusion detection and prevention system.
- Log in to your Netgate pfSense device.
- Configure remote logging options for Netgate pfSense.
Important: If the System Events logging option is enabled, Unknown or Stored events might occur because extra services that are installed by packages for Netgate pfSense can output log messages to the system log. Due to the large number of packages available for Netgate pfSense, the DSM was developed to support the base installation of the device. The DSM Editor can be used in this case to create custom parsing for any Unknown or Stored events that result from user installed packages. For more information about the DSM Editor, see the IBM QRadar Administration Guide.Important: If DHCP events are enabled, you must create a Linux® DHCP log source in QRadar to normalize the DHCP events. The Linux DHCP log source must be placed after Netgate pfSense log source in the parsing order. For more information, see Syslog log source parameters for Linux DHCP and Adding a log source parsing order.Important: If you send Snort or Suricata events to QRadar and the log source is not automatically detected, add a Snort log source on the QRadar Console For more information, see Syslog log source parameters for Open Source SNORT.
- Select .
- Click the Settings tab and then go to the Remote Logging Options section.
- Select a Source Address, or use the default.
- Select an IP Protocol or use the default.
- In the Remote log servers options section, enable System Events, Firewall Events, DNS Events, and DHCP Events.
- Optional: Configure the Snort service to output logs to the Netgate pfSense
- Select .
- On the Snort Interface tab, click Edit this Snort interface mapping (pencil icon).
- In the Alert Settings section, enable Send Alerts to System Log.
- Click Save.
- On the Snort Interface tab, click Restart Snort on this interface.