How to Build a Firewall Log Pipeline With NXLog, SQLite, and Cursor

https://hackernoon.imgix.net/images/2jqChkrv03exBUgkLrDzIbfM99q2-07821tl.png

Build a local firewall log pipeline on Windows with NXLog and SQLite, then let Cursor query it read-only — no SIEM required.

You did everything the docs said. Enabled remote logging on the pfSense box, pointed it at your Windows machine, opened UDP 514. Nothing arrived. The Netgate forum has collected threads about this exact silence for over a decade — logs generated but never sent, syslogd quietly dead after a reboot. Somewhere between the firewall and your disk, the event vanished — and nothing in the chain will tell you where.

The standard fix is a SIEM, which trades one problem for a bigger one: now you own Elasticsearch. This guide takes a different path. You open Cursor, answer five questions, and approve commands while an AI agent builds the firewall log pipeline. By the end you’ll have one verified firewall event on disk, searchable history in a local...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE