New

The executive guide to generative AI

Read more
Loading

Iptables Integration

Version 1.20.0 (View all)
Compatible Kibana version(s) 8.7.1 or higher
9.0.0 or higher
Supported Serverless project types
What's this?
Security
Observability
Subscription level
What's this?
Basic
Level of support
What's this?
Elastic

This is an integration for iptables and ip6tables logs. It parses logs received over the network via syslog (UDP), read from a file, or read from journald. Also, it understands the prefix added by some Ubiquiti firewalls, which includes the rule set name, rule number, and the action performed on the traffic (allow/deny).

The module is by default configured to run with the udp input on port 9001. However, it can also be configured to read from a file path or journald.

This is the Iptables log dataset.