Hello Wazuh Team,
Hope you are all doing well,
I'm facing an issue with aws-s3 integration specifically the cloudwatch service
I can Find the logs in archives.log however it's not being decoded therefore I created a custom decoders and it worked !! but only on testing tools for decoders and rules
in archives.log all cloudwatch logs start with 2023 Oct 18 01:06:55 wazuh->Wazuh-AWS
and after it is json data
I just want to know if should created decoders based on wazuh->Wazuh-AWS or is it being ignored by the SIEM Rules engine and I should use json
Thanks
Abdulaziz