# New pfSense integration added to Github, is there's any planned support for Elastic Agent FreeBSD OS?

**URL:** <https://discuss.elastic.co/t/new-pfsense-integration-added-to-github-is-theres-any-planned-support-for-elastic-agent-freebsd-os/286970>\
**Category:** Beats\
**Tags:** elastic-agent\
**Created:** [October 18, 2021, 10:15am UTC](https://discuss.elastic.co/t/new-pfsense-integration-added-to-github-is-theres-any-planned-support-for-elastic-agent-freebsd-os/286970 "2021-10-18T10:15:55Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![eldadpuzach](https://avatars.discourse-cdn.com/v4/letter/e/ee59a6/32.png) [@eldadpuzach](https://discuss.elastic.co/u/eldadpuzach)\
**Post date:** [October 18, 2021, 10:15am UTC](https://discuss.elastic.co/t/new-pfsense-integration-added-to-github-is-theres-any-planned-support-for-elastic-agent-freebsd-os/286970/1 "2021-10-18T10:15:55Z")

</div>

Hello Elastic team:)  
is it possible to utilize the new pfSense integration to ship logs from PfSense to Elastic Cloud?

> **[integrations/packages/pfsense at master · elastic/integrations](https://github.com/elastic/integrations/tree/master/packages/pfsense)**
>
> master/packages/pfsense

AFAIK there's no Elastic Agent available for FreeBSD OS..  
tnx🙏

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [October 18, 2021, 7:30pm UTC](https://discuss.elastic.co/t/new-pfsense-integration-added-to-github-is-theres-any-planned-support-for-elastic-agent-freebsd-os/286970/2 "2021-10-18T19:30:55Z")

</div>

I created the PfSense integration, it receives logs via syslog not via log files on the system itself. You will need to run it on a central location to receive the syslog and it doesn't need to be freeBSD.

---

<div class="post-metadata">

**Author:** ![eldadpuzach](https://avatars.discourse-cdn.com/v4/letter/e/ee59a6/32.png) [@eldadpuzach](https://discuss.elastic.co/u/eldadpuzach)\
**Post date:** [October 19, 2021, 7:09am UTC](https://discuss.elastic.co/t/new-pfsense-integration-added-to-github-is-theres-any-planned-support-for-elastic-agent-freebsd-os/286970/3 "2021-10-19T07:09:18Z")

</div>

Appreciate Your fast response!  
Thank You🙏

---

<div class="post-metadata">

**Author:** ![eldadpuzach](https://avatars.discourse-cdn.com/v4/letter/e/ee59a6/32.png) [@eldadpuzach](https://discuss.elastic.co/u/eldadpuzach)\
**Post date:** [October 20, 2021, 7:17am UTC](https://discuss.elastic.co/t/new-pfsense-integration-added-to-github-is-theres-any-planned-support-for-elastic-agent-freebsd-os/286970/4 "2021-10-20T07:17:44Z")

</div>

For anyone looking to ship pfSense firewall logs to Elastic Cloud,  
our solution was:

1. pfSense UI - send logs to intermediate Linux host via UDP port 9100
2. Linux host - install Elastic Agent
3. Elastic Cloud - Add pfSense integration to Agent policy  
followed this guide:  
[Quick start: Get logs, metrics, and uptime data into the Elastic Stack | Fleet and Elastic Agent Guide [7.15] | Elastic](https://www.elastic.co/guide/en/fleet/current/fleet-quick-start.html)

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [October 20, 2021, 1:07pm UTC](https://discuss.elastic.co/t/new-pfsense-integration-added-to-github-is-theres-any-planned-support-for-elastic-agent-freebsd-os/286970/5 "2021-10-20T13:07:29Z")

</div>

@eldadpuzach Let me know if there is anything that should be added to the PfSense integration. There are definitely more log types that could be added. I'd love the feedback.

---

<div class="post-metadata">

**Author:** ![nemhods](https://avatars.discourse-cdn.com/v4/letter/n/48db29/32.png) [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Post date:** [October 23, 2021, 11:24am UTC](https://discuss.elastic.co/t/new-pfsense-integration-added-to-github-is-theres-any-planned-support-for-elastic-agent-freebsd-os/286970/6 "2021-10-23T11:24:06Z")

</div>

I've been trying the syslog approach mentioned here before. It has the ugly limitation that it can only ship 512 (? or 1024?) bytes of data per log line - which is not enough e.g. for Suricata / Zeek alerts. Back then, I was unable to raise the syslog packet size limitation in pfSense.

I ended up grabbing filebeat 7.10 from the freebsd package sources ([https://pkgs.org/search/?q=beats](https://pkgs.org/search/?q=beats)). This works, but you need to be very careful that you match the exact freebsd version that your pfsense uses.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [October 23, 2021, 2:08pm UTC](https://discuss.elastic.co/t/new-pfsense-integration-added-to-github-is-theres-any-planned-support-for-elastic-agent-freebsd-os/286970/7 "2021-10-23T14:08:09Z")

</div>

Correct. I ran into that issue a long time ago. My solution was to send the suricata logs to Kafka and then have filebeat read from Kafka using the suricata module.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 20, 2021, 4:08pm UTC](https://discuss.elastic.co/t/new-pfsense-integration-added-to-github-is-theres-any-planned-support-for-elastic-agent-freebsd-os/286970/8 "2021-11-20T16:08:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
