Dear Team,
I hope you are doing well.
We previously integrated AWS Security Hub with Wazuh, and at the time of integration the logs were successfully appearing on the Wazuh dashboard. However, currently we are not seeing any Security Hub logs on the dashboard.
Upon checking, we observed that logs are still being generated and stored in the S3 bucket. We also reviewed the ossec.log file and did not find any errors related to this log source. The relevant log entries are shown below:

Since the module appears to be running without errors but the logs are not visible on the Wazuh dashboard, could you please help us identify what additional checks or troubleshooting steps we should perform?
Your guidance on resolving this issue would be greatly appreciated.
Thank you for your support.
Regards,
Chandra
Hello Gustavo,
Thank you for your response.
I have performed the steps you mentioned. I can see that the Security Hub events are being received in the alert.json file; however, they are not appearing on the dashboard.
For your reference, I have also attached the events file.
Could you please review it and let me know if any additional configuration or troubleshooting steps are required?
2.Have you made any recent changes that could have affected this integration?
Ans: No
Regards,
Chandra


Hello Gustavo,
It is working after changing the rule.groups name. Thank you for your time and guidance.
I have attached the screenshot for your reference.

When you mention that the logs are not appearing in the graphical interface, which interface are you referring to exactly?
Discover: If the logs appear there, could you check what value is set for rule.groups?
The AWS module interface
Based on the logs you shared, there don’t appear to be any errors related to this integration, and it seems to be working correctly
--
You received this message because you are subscribed to a topic in the Google Groups "Wazuh | Mailing List" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/drggiJLgeeU/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/wazuh/6a580f92-a623-416e-aaa8-a893b77e9fa6n%40googlegroups.com.
It seems that the events are reaching the Wazuh server, but they are not being fully processed since they cannot be seen in the indexer (Discover / AWS module).
What might be happening here is that there are no rules or decoders defined for these events. To verify this, you can use wazuh-logtest. This will help us determine whether rules are missing for these events.
You can refer to the following documentation to learn how to use wazuh-logtest: https://documentation.wazuh.com/current/user-manual/reference/tools/wazuh-logtest.html
Hello Suvadip Ghosh,
Based on the information you shared, here are some conclusions:
The AWS NLB logs are reaching the Wazuh server and are being processed correctly by the manager.
There are decoders and rules available to process this type of event. In your case, the event is matching rule ID 130101.
From your wazuh-logtest output: