PFELK is a pfSense/OPNsense firewall traffic visualization solution based on ELK stack. It is a highly customizable tool that let’s you have extensive insight into your network traffic.
Key points:
- pfSense/OPNsense support
- openVPN support
- pfSense/Suricata/Snort dashboards with interactive Maps support (MaxMind GeoIp fields, src -> dest locations, Heatmap, etc.)
- deploy with ansible-playbook, docker or script.
https://github.com/3ilson/pfelk
1. Maxmind: Since I don't know the company and it seems its only providing the geoip-database, my question is: Can it be disabled or left out at all?
2. Java: Its my personal preference to avoid using oracle products at all cost. Is openjdk an alternative?
3. Is the geo-graphical visualization all Pfelk can do? Is there a feature list or demo?