Recent posts

PFSense Snort Logstash

less than 1 minute read

I have been working on getting some detailed logging from Snort logs generated through PFSense and thought I would share them. This can also be modified to w...

VMware NSX Firewall Logging with Logstash

less than 1 minute read

So the past day or so I have been working on getting some good detail from my NSX Edge’s (ESG and DLR) and I have been able to get them working very well. Th...

Bro-IDS Logstash Parsing

less than 1 minute read

I have spent the past several days working with Bro-IDS and Logstash parsing and wanted to share this with anyone else who may be doing the same and needs so...

IP Reputation Lookups with Logstash

1 minute read

I had a great question yesterday about how to configure Logstash to integrate IP reputation lookups within Logstash and Kibana without having to copy and pas...

Suricata IDS/IPS VMXNET3

5 minute read

As part of a bigger post coming soon I have been using Suricata IDS and my Logstash server has been getting hammered and unable to keep up (running a single ...