A single pfSense block never becomes a Wazuh alert. Here is why, measured.
You point pfSense at Wazuh, the logs arrive, and the dashboard stays empty. Most people assume the integration is broken. On Wazuh 4.14.7 it usually is not: there are two separate reasons, and one of them is by design. We sent pfSense filterlog lines over UDP syslog to a Wazuh 4.14.7 manager container and read archives.log and alerts.json . Reason 1: rule 87701 carries no_log The stock pfSense…
When pfSense sends firewall block events to Wazuh, the alerts dashboard often remains empty. This is because two separate factors contribute to this outcome. The first reason is that rule 87701 in Wazuh's ruleset does not log firewall events, as indicated by the comment "We don't log firewall events, because they go to their own log file." The second reason is that the pfSense logs arrive in an unexpected format when sent over UDP, which does not trigger the decoder Wazuh uses by default.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.