I noticed that pflog is not being written to.

$ l /var/log/pflog
-rw-r--r--  1 root  wheel  60 Jan 22 00:00 /var/log/pflog

However, the process running pflogd runs as _pflogd. Does this mean I
should chown the log file with user _pflogd?

Also, just noticed now that my /var/log/pflog file doesn't have read perms
for the others group. Would suggest removing that and trying again.
Possible the extra perms are an issue.

I do not know.

l /var/log/pflog
-rw-------  1 root  wheel  60 Jan 22 00:00 /var/log/pflog

Ok. In your original mail, the permissions were different ...

$ ps ax |grep pflog
25478  ??  Is     0:00.01 pflogd: [priv] (pflogd)
25479  ??  S      0:00.03 pflogd: [suspended] -s 116 -f /var/log/pflog (pflogd)
25561  p0  S+     0:00.01 grep pflog

Not really sure what is going on. I tried:
kill -HUP 25479

I would suggest asking this question on the freebsd-pf mailing list then. They can help better I guess.


