Loading

Iptables Integration

<div class="condensed-table">
| | |
| --- | --- |
| Version | 1.17.0 (View all) |
| Compatible Kibana version(s) | 8.7.1 or higher |
| Supported Serverless project types
What’s this? | Security
Observability |
| Subscription level
What’s this? | Basic |
| Level of support
What’s this? | Elastic |

</div>
This is an integration for iptables and ip6tables logs. It parses logs received over the network via syslog (UDP), read from a file, or read from journald. Also, it understands the prefix added by some Ubiquiti firewalls, which includes the rule set name, rule number, and the action performed on the traffic (allow/deny).

The module is by default configured to run with the udp input on port 9001. However, it can also be configured to read from a file path or journald.

This is the Iptables log dataset.