Hi Alex,
i've done the following:
1. Mounted the equivalent for my needs, which is /usr/share/zoneinfo/Europe/Rome into /var/ossec/etc/localtime
2. Compared to the UTC one, this is the output:
UTC (wrong): /var/ossec/etc/localtime.BACKUP: timezone data, version 2, 1 gmt time flag, 1 std time flag, no leap seconds, no transition times, 1 abbreviation char
Europe/Rome (desired): /var/ossec/etc/localtime: timezone data, version 2, 6 gmt time flags, 6 std time flags, no leap seconds, 171 transition times, 6 abbreviation chars
After restarting, the log still seems to be using the UTC format:
{"timestamp":"2022-07-08T12:30:26.270+0000","rule":{"level":3,"description":"Ossec server started.","id":"502","firedtimes":1,"mail":false,"groups":["ossec"],"pci_dss":["10.6.1"],"gpg13":["10.1"],"gdpr":["IV_35.7.d"],"hipaa":["164.312.b"],"nist_800_53":["AU.6"],"tsc":["CC7.2","CC7.3"]},"agent":{"id":"000","name":"wazuh.master"},"manager":{"name":"wazuh.master"},"id":"1657283426.3655","cluster":{"name":"wazuh","node":"manager"},"full_log":"ossec: Ossec started.","decoder":{"name":"ossec"},"location":"wazuh-monitord"}
Regards,
Daniel D.