Hello .
Still not generating alerts in alerts.json
root@wazuh:/var/ossec/bin# ./wazuh-logtestStarting wazuh-logtest v4.2.5
Type one log per line
Dec 22 07:45:19 SA-DC-ALL-SSC-01 %%10SHELL/6/SHELL_CMD(l): -Task=vt0-IPAddr=10.206.104.43-User=supredes; Command is quit
**Phase 1: Completed pre-decoding.
full event: 'Dec 22 07:45:19 SA-DC-ALL-SSC-01 %%10SHELL/6/SHELL_CMD(l): -Task=vt0-IPAddr=10.206.104.43-User=supredes; Command is quit'
timestamp: 'Dec 22 07:45:19'
hostname: 'SA-DC-ALL-SSC-01'
**Phase 2: Completed decoding.
name: 'hp_5500'
action: 'SHELL_CMD(l)'
command: 'i'
dstuser: 'supredes'
id: '6'
srcip: '10.206.104.43'
url: 'SHELL'
**Phase 3: Completed filtering (rules).
id: '81707'
level: '0'
description: 'HP 5500 EI - Informational event'
groups: '['hp', 'hp5500', 'hp-informational']'
firedtimes: '1'
mail: 'False'
--------------------------------------------
root@wazuh:/var/ossec/bin# tail -f /var/log/sa-dc-all-ssc-01.log | grep SA-DC-ALL-SSC-01
Dec 22 07:34:38 SA-DC-ALL-SSC-01 %%10SC/6/SC_AAA_SUCCESS(l): -AAAType=AUTHEN-AAAScheme= local-Service=login-UserName=supredes@system; AAA is successful.
Dec 22 07:34:38 SA-DC-ALL-SSC-01 %%10SC/6/SC_AAA_LAUNCH(l): -AAAType=AUTHOR-AAAScheme= local-Service=login-UserName=supredes@system; AAA launched.
Dec 22 07:34:38 SA-DC-ALL-SSC-01 %%10SC/6/SC_AAA_SUCCESS(l): -AAAType=AUTHOR-AAAScheme= local-Service=login-UserName=supredes@system; AAA is successful.
Dec 22 07:34:38 SA-DC-ALL-SSC-01 %%10SC/6/SC_AAA_LAUNCH(l): -AAAType=ACCOUNT-AAAScheme= local-Service=login-UserName=supredes@system; AAA launched.
Dec 22 07:34:38 SA-DC-ALL-SSC-01 %%10SC/6/SC_AAA_SUCCESS(l): -AAAType=ACCOUNT-AAAScheme= local-Service=login-UserName=supredes@system; AAA is successful.
Dec 22 07:34:38 SA-DC-ALL-SSC-01 %%10SHELL/4/LOGIN(t): Trap 1.3.6.1.4.1.25506.2.2.1.1.3.0.1:supredes login from VTY
Dec 22 07:34:38 SA-DC-ALL-SSC-01 %%10SHELL/5/SHELL_LOGIN(l): supredes logged in from 10.206.104.43.
Dec 22 07:34:42 SA-DC-ALL-SSC-01 %%10SHELL/6/SHELL_CMD(l): -Task=vt0-IPAddr=10.206.104.43-User=supredes; Command is system-view
Dec 22 07:34:55 SA-DC-ALL-SSC-01 %%10SHELL/6/SHELL_CMD(l): -Task=vt0-IPAddr=10.206.104.43-User=supredes; Command is disp current-configuration
Dec 22 07:44:27 SA-DC-ALL-SSC-01 %%10SHELL/6/SHELL_CMD(l): -Task=vt0-IPAddr=10.206.104.43-User=supredes; Command is disp vlan
-
-----------------------
root@wazuh:/var/ossec/bin# tail -f /var/ossec/logs/alerts/alerts.json | grep SA-DC-ALL-SSC-01
{"timestamp":"2021-12-22T07:50:04.150-0300","rule":{"level":3,"description":"HP 5500 EI - Warning event","id":"81705","firedtimes":1,"mail":true,"groups":["hp","hp5500","hp-warning"]},"agent":{"id":"000","name":"wazuh"},"manager":{"name":"wazuh"},"id":"1640170204.5817228576","full_log":"Dec 22 07:50:03 SA-DC-ALL-SSC-01 %%10SHELL/4/LOGOUT(t): Trap 1.3.6.1.4.1.25506.2.2.1.1.3.0.2:supredes logout from VTY","predecoder":{"timestamp":"Dec 22 07:50:03","hostname":"SA-DC-ALL-SSC-01"},"decoder":{"name":"hp_5500"},"data":{"action":"LOGOUT(t)","id":"4","url":"SHELL"},"location":"/var/log/syslog"}
{"timestamp":"2021-12-22T07:50:14.192-0300","rule":{"level":3,"description":"HP 5500 EI - Warning event","id":"81705","firedtimes":2,"mail":true,"groups":["hp","hp5500","hp-warning"]},"agent":{"id":"000","name":"wazuh"},"manager":{"name":"wazuh"},"id":"1640170214.5818388680","full_log":"Dec 22 07:50:14 SA-DC-ALL-SSC-01 %%10SHELL/4/LOGIN(t): Trap 1.3.6.1.4.1.25506.2.2.1.1.3.0.1:supredes login from VTY","predecoder":{"timestamp":"Dec 22 07:50:14","hostname":"SA-DC-ALL-SSC-01"},"decoder":{"name":"hp_5500"},"data":{"action":"LOGIN(t)","id":"4","url":"SHELL"},"location":"/var/log/syslog"}