Decoder for OPNsense Firewall for logs

366 views
Skip to first unread message

Vivek Kumar

unread,
Sep 18, 2023, 5:43:16 AM9/18/23
to Wazuh | Mailing List
Hi Everyone 

i am new to this product and we have a OPNsense firewall running in our environment, in the Wazuh decoder list i can see decoders for most vendors and technologies but couldn't find decoder for OPNsense Firewall.

Can anyone help me to provide decoders for OPNsense which i can import in wazuh or create decoder for OPNsense.
Appreciate any help.

Regards
Vivek Kumar 

Isaac Yusuf

unread,
Sep 18, 2023, 6:51:34 AM9/18/23
to Wazuh | Mailing List
Hello Vivek,

I can confirm that at this moment, we do not have out-of-the-box decoders for OPNsense.
However, you can consider opening a feature request for our development team to include it in their roadmap to have it as a default decoder.

Another approach is that with Wazuh, you can monitor pretty much anything that has a log. OPNsense needs to have a log file which you most likely have configured by now. Then, you can configure the collection of that log file:

  1. Configuring Wazuh to collect that log. Wazuhs Log data collection capabilities give an overview of how to collect logs with Wazuh.

  2. Here you can learn how to write decoders and rules which is the part you are left with.

When we receive the logs, you can go ahead to create decoders/rules which will then generate alerts.

To create a decoder, you can leverage which explains the process. Below is how to go about it:

  1. From your Dashboard. → Wazuh Menu → Management → Decoder

  2. Click on Custom Decoders → Add new decoders file →

  3. Save the new decoder file name with a name of your choice and modify the file based on instructions on the to suit your logs

  4. During the creation, it is noted also to bear it in mind to take advantage of our RegEx which can help in creating complex decoders.

    Save the decoder and restart the manager:

  5. Test your new decoder using the Wazuh testing tool following sample logs that have been ingested into the Wazuh environment.

 

Here are also some previous users who have had to create OPNsense which might be a great start for your use case:

https://groups.google.com/g/wazuh/c/iYBTHZLer5U/m/0tvFv0TXAQAJ

https://groups.google.com/g/wazuh/c/TefUGoZXC_I/m/Pi-vrMDyBwAJ



https://wazuh.slack.com/archives/C0A933R8E/p1687778716295019


I hope this helps with your concern.



Reply all
Reply to author
Forward
0 new messages