Re: pflogd failing to capture a log record

Stuart Henderson <[email protected]>
Newsgroups gmane.os.openbsd.tech
Message-ID <[email protected]>
On 2026/07/06 15:33, Alexandr Nedvedicky wrote:
> Hallo Jacob,
> 
> the error message comes from pflogd(8) here (sbin/pflogd/pflogd.c):
> 
>     557 /* append packet to the buffer, flushing if necessary */
>     558 void
>     559 dump_packet(u_char *user, const struct pcap_pkthdr *h, const u_char *sp)
>     560 {
>     561         FILE *f = (FILE *)user;
>     562         size_t len = sizeof(*h) + h->caplen;
>     563
>     564         if (len < sizeof(*h) || h->caplen > (size_t)cur_snaplen) {
>     565                 logmsg(LOG_NOTICE, "invalid size %zu (%d/%d), packet dropped",
>     566                        len, cur_snaplen, snaplen);
>     567                 packets_dropped++;
>     568                 return;
>     569         }
> 
> > Jul?? 2 14:35:33 mystic pflogd[77507]: invalid size 180 (160/256), packet
> > dropped
> > 
> 
>     the '(160/256)' in log indicates the pflogd's snaplen must be increased
>     from 160 (default) to 256 bytes. According to pflogd(8) manpage you need
>     to start your pflogd process as follows:
> 
> 	pflogd -s 256
> 
> if you run daemon by rc scripts at boot time you need to run command:
> 
>     rcctl set pflogd flags '-s 256'
>     rcctl reload pflogd
> 
> this should get you going.
> 
> good luck
> and regards
> sashan
> 

You'll need to rotate the log file manually if changing snaplen.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.