Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Alerts not showing properly

    Scheduled Pinned Locked Moved pfBlockerNG
    11 Posts 4 Posters 1.2k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G Offline
      guardian Rebel Alliance
      last edited by

      Unless I misunderstand the way things are supposed to work, the alerts don't seem to be working properly. I get the following display on the dashboard:

      0_1545349299361_fc0fe199-025f-4f74-8ba5-d353d2ac283d-image.png

      When I clicked on the 11 and the 65 I get the following display:

      0_1545349519270_86d0b52f-f90c-46b5-8303-426f45ae7c80-image.png

      I clicked on Apply Filter to update the search, and I still got no entries.

      Am I doing something incorrectly, or have I found a bug?

      If you find my post useful, please give it a thumbs up!
      pfSense 2.7.2-RELEASE

      1 Reply Last reply Reply Quote 0
      • RonpfSR Offline
        RonpfS
        last edited by

        Maybe those log entries are no longer present in the Firewall log?
        I set my box to use 10MB for Log file size (Bytes) in the Status / System Logs / Settings tab

        2.4.5-RELEASE-p1 (amd64)
        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

        1 Reply Last reply Reply Quote 0
        • BBcan177B Offline
          BBcan177 Moderator
          last edited by

          Install pfBlockerNG-devel which has a new logging method which doesn't rely on the pfSense filter.log

          "Experience is something you don't get until just after you need it."

          Website: http://pfBlockerNG.com
          Twitter: @BBcan177  #pfBlockerNG
          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

          G 1 Reply Last reply Reply Quote 1
          • G Offline
            guardian Rebel Alliance @BBcan177
            last edited by

            @bbcan177 said in Alerts not showing properly:

            Install pfBlockerNG-devel which has a new logging method which doesn't rely on the pfSense filter.log

            Thanks for the reply - before I do that a couple of questions:

            • Since it's pfBlockerNG-devel - I assume that means "development" and essentially "beta" software?
            • I would assume this means a much faster update cycle with "beta" software?
            • How long until that feature from the development branch becomes the stable branch?

            I don't really have the time/skill to deal with anything that might crash my firewall so I'll have to wait till the changes trickle down

            BTW... How do I clear those counters? I clicked on the trash can and only the DNSBL counts cleared.

            Thanks again @bbcan177 for all your great work--makes me proud to be Canadian!

            "Experience is something you don't get until just after you need it."
            Ain't that the truth!

            @ronpfs said in Alerts not showing properly:

            Maybe those log entries are no longer present in the Firewall log?
            I set my box to use 10MB for Log file size (Bytes) in the Status / System Logs / Settings tab

            Thanks @ronpfs I think you might be right - I just set set mine for 20MB.

            If you find my post useful, please give it a thumbs up!
            pfSense 2.7.2-RELEASE

            RonpfSR BBcan177B 2 Replies Last reply Reply Quote 0
            • RonpfSR Offline
              RonpfS @guardian
              last edited by RonpfS

              @guardian
              BTW :
              NOTE: Log sizes are changed the next time a log file is cleared or deleted. To immediately increase the size of the log files, first save the options to set the size, then clear all logs using the "Reset Log Files" option farther down this page.

              Mines are still at 500KBs ☹ I didn't reset the log then. I just did.

              The settings was set before restoring the config to a new installation of 2.4.4_p1, that explain why I didn't notice at the time. 😌

              2.4.5-RELEASE-p1 (amd64)
              Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
              Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

              G 1 Reply Last reply Reply Quote 1
              • G Offline
                guardian Rebel Alliance @RonpfS
                last edited by

                @ronpfs said in Alerts not showing properly:

                @guardian
                BTW :
                NOTE: Log sizes are changed the next time a log file is cleared or deleted. To immediately increase the size of the log files, first save the options to set the size, then clear all logs using the "Reset Log Files" option farther down this page.

                Mines are still at 500KBs ☹ I didn't reset the log then. I just did.

                I actually noticed that and reset the logs, but thanks for mentioning it.

                If you find my post useful, please give it a thumbs up!
                pfSense 2.7.2-RELEASE

                1 Reply Last reply Reply Quote 0
                • BBcan177B Offline
                  BBcan177 Moderator @guardian
                  last edited by

                  @guardian
                  https://forum.netgate.com/topic/135708/is-pfblockerng-devel-stable

                  "Experience is something you don't get until just after you need it."

                  Website: http://pfBlockerNG.com
                  Twitter: @BBcan177  #pfBlockerNG
                  Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                  G 1 Reply Last reply Reply Quote 0
                  • G Offline
                    guardian Rebel Alliance @BBcan177
                    last edited by guardian

                    @bbcan177 said in Alerts not showing properly:

                    @guardian
                    https://forum.netgate.com/topic/135708/is-pfblockerng-devel-stable

                    Thanks @bbcan177... I read the post... 3 months ago there was a reference to pushing the devel to production. Did that happen with the recent release of 2.4.4-p1? or is that about to happen soon?

                    How can I clear the counters that I mention in the original post?

                    I'm tempted to try -devel, but I need to know what's my fallback position. I've spent a lot of time setting up blocklists and I don't want to have to go through that mess again.

                    I'm not a network engineer, and if my pfSense goes bye-bye, I have no access to the internet and a managed switch that I can't route.... In short I'm F@*ked, so rollback has got to be very very simple. That's why I skipped 2.4.4 and waited for 2.4.4-p1 to avoid problems.

                    If you find my post useful, please give it a thumbs up!
                    pfSense 2.7.2-RELEASE

                    BBcan177B 1 Reply Last reply Reply Quote 0
                    • BBcan177B Offline
                      BBcan177 Moderator @guardian
                      last edited by

                      @guardian said in Alerts not showing properly:

                      Thanks @bbcan177... I read the post... 3 months ago there was a reference to pushing the devel to production. Did that happen with the recent release of 2.4.4-p1? or is that about to happen soon?
                      How can I clear the counters that I mention in the original post?
                      I'm tempted to try -devel, but I need to know what's my fallback position. I've spent a lot of time setting up blocklists and I don't want to have to go through that mess again.
                      I'm not a network engineer, and if my pfSense goes bye-bye, I have no access to the internet and a managed switch that I can't route.... In short I'm F@*ked, so rollback has got to be very very simple. That's why I skipped 2.4.4 and waited for 2.4.4-p1 to avoid problems.

                      The two version share the same configuration files, so you can always flip back... but I am sure that once you install devel, you will stick with it... The only caveat to flipping back would be the need to reconfigure the IP Interface settings, as devel has merged the IPsec/OVPN interfaces into one option. Also EasyList category settings would need to be reconfigured.

                      In the release version of pfB, there is no btn to clear the IP counters, you would have to run a Filter Reload I think to clear them, or script something with a pfctl shell command. Devel has this already completed in the widget.

                      But as always, you have to ensure you have backups, and a disaster recovery plan. You can always spin up a test VM with your existing config, and play with it before hand.

                      The only issue would be to ensure that you are on pfSense 2.4, since the Devel package uses PHPv7 and is no longer compatible with pfSense 2.3.x

                      "Experience is something you don't get until just after you need it."

                      Website: http://pfBlockerNG.com
                      Twitter: @BBcan177  #pfBlockerNG
                      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                      G 1 Reply Last reply Reply Quote 0
                      • G Offline
                        guardian Rebel Alliance @BBcan177
                        last edited by guardian

                        Thanks for the followup @bbcan177... a couple of questions:

                        @bbcan177 said in Alerts not showing properly:

                        The two version share the same configuration files, so you can always flip back... but I am sure that once you install devel, you will stick with it... The only caveat to flipping back would be the need to reconfigure the IP Interface settings, as devel has merged the IPsec/OVPN interfaces into one option. Also EasyList category settings would need to be reconfigured.

                        You can always spin up a test VM with your existing config, and play with it before hand.

                        Realistically how can I do this? To test my setup I need multiple NICs, and the VM would have to take control of my managed switch. I have multiple VLANs, and without pfSense the whole setup falls apart.

                        The only issue would be to ensure that you are on pfSense 2.4, since the Devel package uses PHPv7 and is no longer compatible with pfSense 2.3.x
                        Thanks for the warning, but at least that's not an issue as I am on 2.4.4-p1.

                        What is the approach to switching? Is it as simple as uninstalling 2.1.4_14 and leaving keep settings checked, and then installing pfBlockerNG-devel 2.2.5_19? I have OpenVPN clients and servers, but no IPsec - anything I would have to change?

                        How long before pfBlockerNG-devel 2.2.5_19 becomes "non-devel"?

                        If you find my post useful, please give it a thumbs up!
                        pfSense 2.7.2-RELEASE

                        1 Reply Last reply Reply Quote 0
                        • S Offline
                          StyleNZ
                          last edited by

                          Hi, I believe I had run into this exact issue myself and this happened upon across multiple installs of it too.

                          I narrowed it down to the fact that some of the log files were not being created for any odd reason. For each of the log files, make sure they exist, and if they don't, manually create them using touch.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.