A firewall without logs is a routing device with a personality. Production OPNsense needs every relevant event — firewall decisions, DNS queries, VPN sessions, IDS alerts, hardware telemetry — to land in a place where the operator can search, alert, and audit. This checklist covers the local log handling, the remote shipping, the metrics integration, and the meta-monitoring that catches a silent firewall.
When to use
Use this checklist before a new OPNsense firewall is connected to the SIEM or log lake, before any change to the logging pipeline, and after any incident where logs were missing. It also pairs with the backup / DR checklist, because the log pipeline and the backup pipeline are often the same operational infrastructure.
How to use
Walk the list while reviewing the logging destinations, the SIEM ingestion, and the alert rules. Capture a sample of each log type to confirm the SIEM is parsing it correctly. Mark each item and file the change with the operator’s change system.