Outstanding product. M$ should have provided this 'out of the box'.
Question: Is there a way to setup Monilog to Group "firewall" syslogs the way that it does for NT Logs?
I could then see that I had:
5 VPN connection attempts
6000 port scans
50 attempts to get to port 21
etc, etc
Is this possible?
Thanks!

