Skip to content
Discussion options

You must be logged in to vote

Starting in 2.4.40, the rule.action field is now event.action to align with the Elastic integration for pfSense. If you're in SOC Dashboards and you use our default Firewall dashboard, it should have been updated to reflect this change:

For more information about this change, please see:
https://docs.securityonion.net/en/2.4/release-notes.html
#12021
6a1073b

If you haven't already, you might want to consider switching to the more comprehensive pfSense integration as it will parse more log types:
https://docs.securityonion.net/en/2.4/pfsense.html#elastic-integration-for-pfsense

We just released a video about this yesterday:
https://www.youtube.com/watch?v=aoH8qZwAxek

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@arisentow
Comment options

@dougburks
Comment options

Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants