I was want to say that im close to logstash grok patterns for OpenVPN pfSense Logs.
I just have one tiny issue I cannot get or understand why maybe im missing a } not sure.
So after implementing the OpenVPN paterns it works perfect but then my GeoIP stops working. not sure why, as you can see the RAW data stops showing the patterns while on the RAW data without OpenVPN shows the GeoIP not sure what I missed
Raw data with OpenVPN---- http://pastebin.com/wedNp5Wt
Raw data WITHOUT OpenVPN----- http://pastebin.com/iLvkkdw8