Indeed, this is what I typically do. and make sure I only log the real mailserver connections to pflog1, and point spamlogd at that.
On Wed, Mar 6, 2013 at 2:14 PM, Stuart Henderson <s...@spacehopper.org> wrote: > On 2013/03/06 13:47, Bob Beck wrote: >> No constantine - the solution is to simply not use the "log" keyword >> on such traffic > > Or you can use an alternative log interface > > log (to <interface>) > Send logs to the specified pflog(4) interface instead of pflog0. >