Parse pfSense/OPNSense logs using Logstash, GeoIP tag entities, add additional context to logs, then send to Azure Sentinel for analysis.
visualization logstash parse monitor analytics sentinel opnsense geoip maxmind pfsense maxmind-geoip firewall-logs pfsense-logs kql sentinel-dashboard azure-sentinel opnsense-firewall pfsense-firewall opnsense-logs linux-oms
-
Updated
Feb 28, 2022