I had a line which had frequent but short-lived Blacklistings. As a result of the behaviour it hasn't been possible to get a packet capture to see just what's going on with the line; it may not be an "attack" and could be a wayward service.
If there was the ability to automatically save a packet capture before a line is Blacklisted it would help with diagnosis.