{
  "id": 11811186,
  "title": "A single pfSense block never becomes a Wazuh alert. Here is why, measured.",
  "url": "https://urgent.news/2026/10/04/a-single-pfsense-block-never-becomes-a-wazuh-alert-here-is-why",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-04T01:08:44.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/xuxu298/a-single-pfsense-block-never-becomes-a-wazuh-alert-here-is-why-measured-563m"
  },
  "original_language": "en",
  "account": "When pfSense sends firewall block events to Wazuh, the alerts dashboard often remains empty. This is because two separate factors contribute to this outcome. The first reason is that rule 87701 in Wazuh's ruleset does not log firewall events, as indicated by the comment \"We don't log firewall events, because they go to their own log file.\" The second reason is that the pfSense logs arrive in an unexpected format when sent over UDP, which does not trigger the decoder Wazuh uses by default.",
  "summary": "You point pfSense at Wazuh, the logs arrive, and the dashboard stays empty. Most people assume the integration is broken. On Wazuh 4.14.7 it usually is not: there are two separate reasons, and one of them is by design. We sent pfSense filterlog lines over UDP syslog to a Wazuh 4.14.7 manager container and read archives.log and alerts.json . Reason 1: rule 87701 carries no_log The stock pfSense…",
  "key_points": [
    "Wazuh alerts lack firewall block events from pfSense",
    "Rule 87701 in Wazuh ruleset doesn't log firewall events",
    "Unexpected UDP format of pfSense logs prevents decoder trigger"
  ],
  "editors_take": "The integration of pfSense with Wazuh is hindered by a combination of Wazuh's rule configuration and log format issues, preventing block events from generating alerts.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}