Build PFSense to Send Logs To Splunk and Splunk Receives them
Step 1 — Set Up Splunk to Receive Syslog
Splunk needs to open a "door" (a network port) to listen for incoming syslog messages. The standard syslog port is 514/UDP.
In Splunk web:
Click Settings (top right) → Data inputs
Find UDP in the list → click + Add new (or "New Local UDP")
Set Port to 514
Click Next