Hello team,
I have enabled and configured agent less monitoring to send fortigate firewall logs to wazuh as follow:
<remote>
<connection>syslog</connection>
<allowed-ips>
172.18.0.0/16</allowed-ips>
<protocol>udp</protocol>
<port>514</port>
</remote>
I am receiving fortigate firewall logs in archieve and alerts.log.
I can see that the wazuh alerts index is filled with log.
green open wazuh-alerts-4.x--2023.11.27 68_OCc16Td2QASzKwCP1uQ 3 0 221392 0 537.8mb 537.8mb
But i don't see alerts on opensearch dashboard.