Thanks a lot, you are rigth, I will tell it to the correct team for update the documentation.
However , for your log you add modify other things in your regex like this
<decoder name="mikrotik1">
<parent>mikrotik</parent>
<regex type="pcre2">\S+ (\w+ \d+:\d+:\d+) Mikrotik Router user (\S+) (.*?) from (\d+.\d+.\d+.\d+) via (\w+)</regex>
<order>logtimestamp, logged_user, action, ip_address, protocol</order>
</decoder>
output:
ulian-A15-FA506QM:/home/thejbte# /var/ossec/bin/wazuh-logtest
Starting wazuh-logtest v4.9.0
Type one log per line
RouterOS7.1-logs: 2024-04-22T06:23:08.879433900Z {ip=192.168.10.1} <24>Apr 22 09:23:07 Mikrotik Router user admin logged in from 192.168.10.182 via winbox
**Phase 1: Completed pre-decoding.
full event: 'RouterOS7.1-logs: 2024-04-22T06:23:08.879433900Z {ip=192.168.10.1} <24>Apr 22 09:23:07 Mikrotik Router user admin logged in from 192.168.10.182 via winbox'
**Phase 2: Completed decoding.
name: 'mikrotik'
action: 'logged in'
ip_address: '192.168.10.182'
logged_user: 'admin'
logtimestamp: '22 09:23:07'
protocol: 'winbox'
Best regards