<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Monitoring pfBlockerNG with SyslogNG: but SyslogNG sends the same entire log file each hour to Syslog Server]]></title><description><![CDATA[<p dir="auto">Dear Users,</p>
<p dir="auto">I just installed and configured pfBlockerNG on a pfSense 2.6 instance and I decided to monitor the pfBlockerNG using SyslogNG.<br />
SyslogNG collect the relevant logs (file /var/log/pfBlockerNG/IP_block.log) and send them to the log collector (SIEM).</p>
<p dir="auto">So, at the end of this work, I'm able to analyse the logs using the web UI of the SIEM (Wazuh in my case).</p>
<p dir="auto">PROBLEM: I noticed that, on a hourly basis, the entire log file content is sent to the SIEM. Due to this behaviour, the same alerts are processed multiple times by the SIEM.</p>
<p dir="auto">Could you please help me to stop this anomaly? Anyone of you already faced this problem?</p>
<p dir="auto">Thank you in advance,<br />
Mauro</p>
]]></description><link>https://forum.netgate.com/topic/180751/monitoring-pfblockerng-with-syslogng-but-syslogng-sends-the-same-entire-log-file-each-hour-to-syslog-server</link><generator>RSS for Node</generator><lastBuildDate>Sun, 10 May 2026 04:33:42 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/180751.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 10 Jun 2023 17:11:49 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Monitoring pfBlockerNG with SyslogNG: but SyslogNG sends the same entire log file each hour to Syslog Server on Sat, 10 Jun 2023 19:47:08 GMT]]></title><description><![CDATA[<p dir="auto">@mauro-tridici To be honest i set mine up to daily updates months before I started using Syslog-ng, because I thought hourly updates are unnessecary. Even on daily updates it’s rare there is changes to the lists that I use, so this is a fine compromise for me.</p>
]]></description><link>https://forum.netgate.com/post/1109900</link><guid isPermaLink="true">https://forum.netgate.com/post/1109900</guid><dc:creator><![CDATA[keyser]]></dc:creator><pubDate>Sat, 10 Jun 2023 19:47:08 GMT</pubDate></item><item><title><![CDATA[Reply to Monitoring pfBlockerNG with SyslogNG: but SyslogNG sends the same entire log file each hour to Syslog Server on Sat, 10 Jun 2023 18:24:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/keyser">@<bdi>keyser</bdi></a> thank you for your feedback.<br />
I hope someone will give us a solution :) Meanwhile, I can set the pfBlocker update to "once a day (02:00)" as you did.<br />
What do you think about this "workaround" to reduce the reloads events?</p>
<p dir="auto">Have a great weekend,<br />
Mauro</p>
]]></description><link>https://forum.netgate.com/post/1109892</link><guid isPermaLink="true">https://forum.netgate.com/post/1109892</guid><dc:creator><![CDATA[mauro.tridici]]></dc:creator><pubDate>Sat, 10 Jun 2023 18:24:22 GMT</pubDate></item><item><title><![CDATA[Reply to Monitoring pfBlockerNG with SyslogNG: but SyslogNG sends the same entire log file each hour to Syslog Server on Sat, 10 Jun 2023 17:51:03 GMT]]></title><description><![CDATA[<p dir="auto">@mauro-tridici yeah, i noticed the same issue - only in My case it happens once a day (02:00) because thats when i Have pfblocker doing its update.<br />
It seems when pfblocker updates it reloads the logfile in a manner that causes syslog-ng think all the Lines are new.<br />
I have been unable to find a solution so far, so I’ll monitor that thread to see if anyone has a solution</p>
]]></description><link>https://forum.netgate.com/post/1109886</link><guid isPermaLink="true">https://forum.netgate.com/post/1109886</guid><dc:creator><![CDATA[keyser]]></dc:creator><pubDate>Sat, 10 Jun 2023 17:51:03 GMT</pubDate></item></channel></rss>