So I edit agent(docker side) ossec.conf file with this commands: So i can get docker logs possibly
<localfile>
<log_format>syslog</log_format>
<location>/var/log/docker/*</location>
</localfile>
Furthemore, As i mentioned earlier Ionly need to send rspamd logs to wazuh and generate alert on that basis …So, I addedd the path of rspamd container as well with this commands
<localfile>
<log_format>syslog</log_format>
<location>/var/lib/docker/containers/e55dda56492ab3d30166a0f60104af0a8cbec9214b2fc9cef49273c54cb7b793/e55dda56492ab3d30166a0f60104af0a8cbec9214b2fc9cef49273c54cb7b793-json.log</location>
Now am getting alerts on wazuh manger side But am not getting any logs here in archive folder at wazuh manager side
the path i have given is it ok?? or am missing something
I have attached screenshot