Created attachment 240725 [details] patch for FreeBSD 13.1 pflog header format The FreeBSD and OpenBSD pflog header formats have diverged, and the latest changes to FreeBSD's header to support the "ridentifier" field (here: https://reviews.freebsd.org/D32750) are no longer supported by snort. The attached patch adds support for the new header size. Note: the same issue exists in Snort3, and a corresponding PR was submitted with a similar fix here: https://github.com/snort3/snort3_extra/pull/10
Did this get included in a recent release?