Hello Brian,
First of all, my apologies for the late response.
If you are still struggling with this, I recommend moving to the current version of Wazuh Manager (4.2.3) because I tested this and it is decoded and generates the alerts without any issues:
Starting wazuh-logtest v4.2.2
Type one log per line
id=firewall sn=XXXXXX time="2021-02-24 19:28:16" fw=XXXXXXX pri=4 c=16 m=200 msg="CLI administrator login denied due to bad credentials" n=5314 usr="XXXX" src=XXXXXXX fw_action="NA"
**Phase 1: Completed pre-decoding.
full event: 'id=firewall sn=XXXXXX time="2021-02-24 19:28:16" fw=XXXXXXX pri=4 c=16 m=200 msg="CLI administrator login denied due to bad credentials" n=5314 usr="XXXX" src=XXXXXXX fw_action="NA"'
**Phase 2: Completed decoding.
name: 'sonicwall'
action: 'CLI administrator login denied due to bad credentials'
status: '4'
**Phase 3: Completed filtering (rules).
id: '4804'
level: '3'
description: 'SonicWall warning message.'
groups: '['syslog', 'sonicwall']'
firedtimes: '1'
mail: 'False'
**Alert to be generated.
If you have configured your ossec.conf file to generate alert in level 3 events, you will get the same alert you are seeing in the above test.
I hope this could be helpful for you.
--
You received this message because you are subscribed to a topic in the Google Groups "Wazuh mailing list" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/rjj4lQKwbvM/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/676729b3-af2e-4854-b6af-15b54983db4bn%40googlegroups.com.