Build PFSense to Send Logs To Splunk and Splunk Receives them

Step 1 — Set Up Splunk to Receive Syslog

Splunk needs to open a "door" (a network port) to listen for incoming syslog messages. The standard syslog port is 514/UDP.

In Splunk web:


Click Settings (top right) → Data inputs

Find UDP in the list → click + Add new (or "New Local UDP")

Set Port to 514

Click Next