So, bridging a vlan interface with a pflog interface shouldn't be a problem right? They're all interfaces right? So one could practically extend a hosts pflog interface to other hosts this way right?

I guess I'll just have to try and find out.

#openbsd #pf

Nope, my super brilliant plan of briliantness does not seem to work. Interfaces are not created equal. I'll have to figure out another way to feed #suricata pcap data... worst case hack togheter a small deamon that just forwards pflog0 data to vlan12 as intended.