OPNsense
Overview
OPNsense is a FreeBSD-based open-source firewall and routing platform with enterprise-grade features including Suricata IDS/IPS, web proxy, and VPN. KYRA MDR collects OPNsense firewall filter logs, Suricata intrusion detection events, and system authentication logs via syslog for network security monitoring.
Prerequisites
- KYRA MDR account (MDR tier or above)
- KYRA Collector installed and reachable from the OPNsense appliance
- OPNsense 23.1 or later with administrative web interface access
- Network connectivity from OPNsense to the Collector on TCP/UDP port 514
Configuration
Step 1: Configure Remote Syslog Target
- Navigate to System > Settings > Logging / Targets
- Click the + button to add a new remote syslog destination
- Configure the target:
| Setting | Value |
|---|---|
| Enabled | Checked |
| Transport | TCP(4) |
| Applications | Leave empty (sends all) |
| Levels | Leave default (sends all severity levels) |
| Facilities | Leave empty (sends all facilities) |
| Hostname | <COLLECTOR_IP> |
| Port | 514 |
| RFC5424 | Checked (structured syslog format) |
| Certificate | (Optional: select a CA for TLS transport) |
- Click Save and then Apply
Step 2: Enable Detailed Filter Logging
Configure which firewall rules generate log entries:
- Navigate to Firewall > Settings > Normal
- Enable Log packets matched from the default block rules
- Enable Log packets matched from the default pass rules (if needed for full visibility)
- Click Save
For individual rules, edit each rule and check Log packets that are handled by this rule.
OPNsense filter log format (CSV-style via /var/log/filter.log):
rulenr,subrulenr,anchorname,ridentifier,interface,reason,action,direction,ipversion,tos,ecn,ttl,id,offset,flags,proto,protoid,length,src,dst,srcport,dstportStep 3: Configure Suricata IDS Logging
- Navigate to Services > Intrusion Detection > Administration
- Ensure Enabled is checked
- Set IPS mode as needed (IDS for monitoring, IPS for blocking)
- Under General tab, verify:
- Pattern matcher: Aho-Corasick
- Log level: Info
- EVE output: Enabled (JSON-formatted event log)
Download and enable rulesets:
- Go to Services > Intrusion Detection > Administration > Download tab
- Enable rulesets:
ET open/emerging-*(Emerging Threats open rules)abuse.ch(malware/botnet IOCs)
- Click Download & Update Rules
- Go to the Rules tab to enable/disable specific rule categories
Suricata EVE JSON output is written to /var/log/suricata/eve.json:
{ "timestamp": "2024-01-15T10:30:00.000000+0900", "event_type": "alert", "src_ip": "192.168.1.100", "dest_ip": "203.0.113.50", "alert": { "action": "allowed", "signature_id": 2024897, "signature": "ET MALWARE Trickbot Checkin", "category": "A Network Trojan was Detected", "severity": 1 }}Step 4: Configure Syslog via CLI (Alternative)
For advanced syslog configuration, use the OPNsense shell:
# SSH into OPNsensessh root@<OPNSENSE_IP>
# Edit syslog configurationvi /usr/local/etc/syslog.d/kyra-remote.conf
# Add remote syslog target (RFC 5424 over TCP)*.* @@<COLLECTOR_IP>:514;RFC5424fmt# Restart syslog serviceservice syslogd restart
# Verify syslog is sendingsockstat -4l | grep syslogStep 5: Enable TLS for Syslog (Recommended)
For encrypted log transport:
- Navigate to System > Trust > Authorities and import the KYRA Collector CA certificate
- Navigate to System > Settings > Logging / Targets
- Edit the remote target and set Transport to
TLS(6) - Select the imported Certificate for the target
- Click Save and Apply
Step 6: Forward Suricata EVE Logs
If Suricata EVE logs need separate forwarding:
# Use a file watcher to forward EVE JSONmodule(load="imfile" PollingInterval="5")
input(type="imfile" File="/var/log/suricata/eve.json" Tag="suricata-eve" Facility="local6" Severity="info")
local6.* @@<COLLECTOR_IP>:514Verify on KYRA Collector
kyra-collector statuskyra-collector logs --source opnsense --tail 10Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Filter Log | Firewall pass/block decisions with source, destination, port, protocol | Network access monitoring |
| Suricata Alerts | IDS/IPS signature matches with severity and classification | Threat detection |
| Suricata EVE | Full JSON event log including DNS, HTTP, TLS, file transactions | Deep protocol inspection |
| System Auth | Login, logout, sudo, SSH events on the OPNsense host | Management plane security |
| OpenVPN | VPN tunnel connect, disconnect, authentication events | Remote access monitoring |
| Unbound DNS | DNS query and response logs | DNS security, C2 detection |
| Web Proxy | HTTP/HTTPS proxy access logs | Web filtering, data exfiltration |
| DHCP | DHCP lease events | IP address tracking |
Key OPNsense Syslog Facilities
| Facility | Source | Description |
|---|---|---|
filterlog | pf firewall | Firewall filter decisions |
suricata | Suricata IDS | Intrusion detection alerts |
openvpn | OpenVPN | VPN connection events |
unbound | Unbound DNS | DNS resolver logs |
configd | Configuration daemon | Configuration change events |
audit | Authentication | Login and privilege events |
Troubleshooting
- No syslog received: Verify the logging target is enabled and the transport matches the Collector expectation (TCP vs UDP). Check System > Settings > Logging / Targets for status.
- Filter logs missing: Ensure individual firewall rules have Log enabled, or enable default block/pass logging under Firewall > Settings > Normal.
- Suricata not alerting: Verify Suricata is running under Services > Intrusion Detection > Administration. Check that rulesets are downloaded and rules are enabled.
- Timestamps incorrect: Enable RFC5424 format in the syslog target for ISO 8601 timestamps. Verify NTP is configured under Services > Network Time > General.
- TLS connection failing: Verify the CA certificate is imported and the Collector supports TLS syslog on the configured port. Check OPNsense logs under System > Log Files > General.
- High filter log volume: Exclude noisy rules (e.g., broadcast traffic) from logging by unchecking Log on those specific firewall rules.
Contact kyra@seekerslab.com for integration support.