Yes, I did get this set up although not via NRPE:
- Log OSSEC alerts for a certain level to Elasticsearch/Logstash and Kibana
- Nagios runs a query on Kibana for this alert level and displays the alerts in a nagios dashboard. (the alert stays there for 24 hours and is then auto removed after 24 hour).
This setup is far from ideal as it is a passive check and stays there for only 24 hours.
I also don’t know the fine technical details how to set this up (since someone else’s set it up with Nagios).
But this is the general idea how it works at our company.
Cheers,