Thank you, Maurya, for the details.
I wanted to ask if you were able to find the logs you want to export within the Wazuh platform. Regarding exporting it via a script, could you please provide more information about that?
Regards
Apologies, I'll add one more query to better understand the context of your issue. Would the central components of Wazuh be installed on an EC2 instance?
I'll await your response.
Regards
Antonio
--
You received this message because you are subscribed to a topic in the Google Groups "Wazuh | Mailing List" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/wabOSjj55xM/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/6b5ddf40-8e83-44e8-8fb7-1ef9bd359e23n%40googlegroups.com.
Hello, dear Maurya Poonam.
So, I understand that you have successfully installed the core components of Wazuh (manager, indexer, filebeat, dashboard) on an EC2 instance. What you are looking to do is transfer log and alert information in real time to an S3 bucket.
To begin, it's important for you to know that the log files are located in /var/ossec/logs. Alert logs are stored in /var/ossec/alerts. General logs in ossec.log rotate daily and are stored in /var/ossec/logs/wazuh according to the month and day. There logs related to API and Clusters that you can find also in /var/ossec/logs.
These files (which you aim to transfer in real time to S3) should be managed by an AWS data transfer system, as this functionality is not native to Wazuh. After my research, I have found that the most suitable solution for real-time transfer would be to use AWS DataSync. Here is the link to the official AWS documentation: https://docs.aws.amazon.com/datasync/latest/userguide/what-is-datasync.html
I have also come across this article: https://michaelsambol.medium.com/move-millions-of-files-from-amazon-ec2-to-amazon-s3-using-aws-datasync-a15bb31a81a1
These are the most immediate solutions I found during my research. If you would like us to implement these together or if you want to explore other solutions, I am here and available to assist. If you're willing to share your code and would like us to explore the
solution you've been working on together, I would appreciate a more
detailed explanation of your approach. I commit to working on finding a
solution with you.
Antonio
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/bdc9be47-02cf-4572-9eff-25bd0b65502cn%40googlegroups.com.
Feel free to use the reference link I shared with you here where you can find a more detailed step-by-step guide.
If you have any questions, I'm here to help with whatever you need.