# Using beats in pfsense firewall to get system logs

**URL:** <https://discuss.elastic.co/t/using-beats-in-pfsense-firewall-to-get-system-logs/113749>\
**Category:** Beats\
**Created:** [January 2, 2018, 10:18am UTC](https://discuss.elastic.co/t/using-beats-in-pfsense-firewall-to-get-system-logs/113749 "2018-01-02T10:18:01Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![rahul01](https://avatars.discourse-cdn.com/v4/letter/r/b5e925/32.png) [@rahul01](https://discuss.elastic.co/u/rahul01)\
**Post date:** [January 2, 2018, 10:18am UTC](https://discuss.elastic.co/t/using-beats-in-pfsense-firewall-to-get-system-logs/113749/1 "2018-01-02T10:18:01Z")

</div>

Hello

I'm using freebsd pfsense 2.4.2, and I want to send system authentication logs to kafka.  
So is it possible to install any beats in pfsense and monitor?

Thanks & Regards  
Rahul

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 4, 2018, 1:11pm UTC](https://discuss.elastic.co/t/using-beats-in-pfsense-firewall-to-get-system-logs/113749/2 "2018-01-04T13:11:39Z")

</div>

1. we don't ship freebsd binaries. You will have to build filebeat yourself
2. I think by default pfsense uses some kind of circular ring (on disk) to store logs. This can of file format can not be processes by filebeat. Make sure to configure pfsense to use plain old log files.

---

<div class="post-metadata">

**Author:** ![rahul01](https://avatars.discourse-cdn.com/v4/letter/r/b5e925/32.png) [@rahul01](https://discuss.elastic.co/u/rahul01)\
**Post date:** [January 4, 2018, 1:40pm UTC](https://discuss.elastic.co/t/using-beats-in-pfsense-firewall-to-get-system-logs/113749/3 "2018-01-04T13:40:01Z")

</div>

Hello @steffens

i tried that also but filebeat script is not excecutable in pfsense.  
Error:-

1. [2.4.2-RELEASE][root@ADPfsense]/root/filebeat: ./filebeat -configtest -e  
ELF binary type "0" not known.  
./filebeat: Exec format error. Binary file not executable.

2. [2.4.2-RELEASE][root@ADPfsense]/root/filebeat: sh filebeat -configtest -e  
filebeat: 1: Syntax error: "(" unexpected

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 5, 2018, 11:21am UTC](https://discuss.elastic.co/t/using-beats-in-pfsense-firewall-to-get-system-logs/113749/4 "2018-01-05T11:21:14Z")

</div>

We don't ship freebsd builds. It fails, because you did try to run a binary build for linux.

---

<div class="post-metadata">

**Author:** ![rahul01](https://avatars.discourse-cdn.com/v4/letter/r/b5e925/32.png) [@rahul01](https://discuss.elastic.co/u/rahul01)\
**Post date:** [January 5, 2018, 11:54am UTC](https://discuss.elastic.co/t/using-beats-in-pfsense-firewall-to-get-system-logs/113749/5 "2018-01-05T11:54:40Z")

</div>

Hello @steffens

So is there any way to install filebeat in pfsense? Please give steps in detail.

Thanks

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 5, 2018, 12:08pm UTC](https://discuss.elastic.co/t/using-beats-in-pfsense-firewall-to-get-system-logs/113749/6 "2018-01-05T12:08:09Z")

</div>

I'm not using FreeBSD, so I can't give you instructions.

Either search for a FreeBSD Port of filebeat, so you can install it with FreeBSD native tools, or you will have to setup a [go development environment](https://golang.org/doc/install) to build filebeat yourself either on FreeBSD itself or via cross compilation.

@andrewkroh Any idea wether FreeBSD nightly builds are available?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 23, 2018, 10:18am UTC](https://discuss.elastic.co/t/using-beats-in-pfsense-firewall-to-get-system-logs/113749/7 "2018-01-23T10:18:49Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
