Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Monitoring pfBlockerNG with SyslogNG: but SyslogNG sends the same entire log file each hour to Syslog Server

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 2 Posters 472 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mauro.tridici
      last edited by

      Dear Users,

      I just installed and configured pfBlockerNG on a pfSense 2.6 instance and I decided to monitor the pfBlockerNG using SyslogNG.
      SyslogNG collect the relevant logs (file /var/log/pfBlockerNG/IP_block.log) and send them to the log collector (SIEM).

      So, at the end of this work, I'm able to analyse the logs using the web UI of the SIEM (Wazuh in my case).

      PROBLEM: I noticed that, on a hourly basis, the entire log file content is sent to the SIEM. Due to this behaviour, the same alerts are processed multiple times by the SIEM.

      Could you please help me to stop this anomaly? Anyone of you already faced this problem?

      Thank you in advance,
      Mauro

      keyserK 1 Reply Last reply Reply Quote 0
      • keyserK
        keyser Rebel Alliance @mauro.tridici
        last edited by

        @mauro-tridici yeah, i noticed the same issue - only in My case it happens once a day (02:00) because thats when i Have pfblocker doing its update.
        It seems when pfblocker updates it reloads the logfile in a manner that causes syslog-ng think all the Lines are new.
        I have been unable to find a solution so far, so I’ll monitor that thread to see if anyone has a solution

        Love the no fuss of using the official appliances :-)

        M 1 Reply Last reply Reply Quote 1
        • M
          mauro.tridici @keyser
          last edited by

          @keyser thank you for your feedback.
          I hope someone will give us a solution :) Meanwhile, I can set the pfBlocker update to "once a day (02:00)" as you did.
          What do you think about this "workaround" to reduce the reloads events?

          Have a great weekend,
          Mauro

          keyserK 1 Reply Last reply Reply Quote 0
          • keyserK
            keyser Rebel Alliance @mauro.tridici
            last edited by

            @mauro-tridici To be honest i set mine up to daily updates months before I started using Syslog-ng, because I thought hourly updates are unnessecary. Even on daily updates it’s rare there is changes to the lists that I use, so this is a fine compromise for me.

            Love the no fuss of using the official appliances :-)

            1 Reply Last reply Reply Quote 2
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.