Hello Nicolas,
here is the wazuh worker nodes logs.
root@wazuh-manager-worker-0:/# /var/ossec/bin/wazuh-logtest -vv
Starting wazuh-logtest v4.5.0
Type one log per line
Sep 5 15:00:01 hostname sudo[1324846]: pam_unix(sudo:session): session opened for user mfe by (uid=0)
full event: 'Sep 5 15:00:01 hostname sudo[1324846]: pam_unix(sudo:session): session opened for user mfe by (uid=0)'
timestamp: 'Sep 5 15:00:01'
hostname: 'hostname'
program_name: 'sudo'
**Phase 2: Completed decoding.
name: 'pam'
parent: 'pam'
dstuser: 'mfe'
uid: '0'
**Rule debugging:
Trying rule: 1 - Generic template for all syslog rules.
*Rule 1 matched
*Trying child rules
Trying rule: 600 - Active Response Messages Grouped
Trying rule: 650 - Active Response JSON Messages Grouped
Trying rule: 200 - Grouping of wazuh rules.
Trying rule: 400 - Rules for Wazuh API events.
Trying rule: 420 - Rules for Wazuh API events.
Trying rule: 2100 - NFS rules grouped.
Trying rule: 2507 - OpenLDAP group.
Trying rule: 2550 - rshd messages grouped.
Trying rule: 2701 - Ignoring procmail messages.
Trying rule: 2800 - Pre-match rule for smartd.
Trying rule: 5100 - Pre-match rule for kernel messages.
Trying rule: 5200 - Ignoring hpiod for producing useless logs.
Trying rule: 2830 - Crontab rule group.
Trying rule: 5300 - Initial grouping for su messages.
Trying rule: 5905 - useradd failed.
Trying rule: 5400 - Initial group for sudo messages.
Trying rule: 9100 - PPTPD messages grouped.
Trying rule: 9200 - Squid syslog messages grouped.
Trying rule: 2900 - Dpkg (Debian Package) log.
Trying rule: 2930 - Yum logs.
Trying rule: 2931 - Yum logs.
Trying rule: 2940 - NetworkManager grouping.
Trying rule: 2943 - nouveau driver grouping.
Trying rule: 2962 - Perdition custom app group.
Trying rule: 3100 - Grouping of the sendmail rules.
Trying rule: 3190 - Grouping of the smf-sav sendmail milter rules.
Trying rule: 3300 - Grouping of the postfix reject rules.
Trying rule: 3320 - Grouping of the postfix rules.
Trying rule: 3390 - Grouping of the clamsmtpd rules.
Trying rule: 3395 - Grouping of the postfix warning rules.
Trying rule: 3500 - Grouping for the spamd rules
Trying rule: 3600 - Grouping of the imapd rules.
Trying rule: 3700 - Grouping of mailscanner rules.
Trying rule: 3800 - Grouping of Exchange rules.
Trying rule: 3900 - Grouping for the courier rules.
Trying rule: 4500 - Grouping for the Netscreen Firewall rules
Trying rule: 4700 - Grouping of Cisco IOS rules
Trying rule: 4800 - SonicWall messages grouped.
Trying rule: 5500 - Grouping of the pam_unix rules.
*Rule 5500 matched
*Trying child rules
Trying rule: 5552 - PAM and gdm are not playing nicely.
Trying rule: 101101 - Ignore sudo auth for mfe user.
*Rule 101101 matched
**Phase 3: Completed filtering (rules).
id: '101101'
level: '0'
description: 'Ignore sudo auth for mfe user.'
groups: '['pam', 'syslog']'
firedtimes: '1'
gdpr: '['IV_32.2']'
gpg13: '['7.6', '7.8', '7.13']'
hipaa: '['164.312.b']'
mail: 'False'
nist_800_53: '['AU.14', 'AC.7', 'AC.6']'
pci_dss: '['10.2.5', '10.2.2']'
tsc: '['CC6.8', 'CC7.2', 'CC7.3']'
Greetings,
Saddique