Even with the default hour of the cron to remove blocked users, I haven't found a way of 'monitoring' this function.
I use this funcion with cront running every two minutes to avoid exernal users being blocked for up to two hours.
*/2 * * * * root /usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 60 virusprot
Am I missing something? is snort a requirement to see users in 'virusprot' table?
No, it's a built in pfsense function