At the moment, Wazuh indexer needs this configuration to be able to receive information from Filebeat, since this configuration enables compatibility with OpenSearch (in which Wazuh indexer is based).
What occurs to me is that you add some other tool for data ingestion to Graylog such as Logstash, but you will have to do these tests on your own.
On Aug 16, 2023, at 8:23 AM, 'Carlos Ezequiel Bordon' via Wazuh mailing list <wa...@googlegroups.com> wrote:
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/9a34890e-1410-4c2c-b494-6e41e127bf9cn%40googlegroups.com.
Yes, it is correct, we have configurations for Filebeat to use our module, I am sharing the files that we use to configure Filebeat.
Configuration file: https://packages.wazuh.com/4.5/tpl/wazuh/filebeat/filebeat.yml
Wazuh template json: https://raw.githubusercontent.com/wazuh/wazuh/4.5/extensions/elasticsearch/7.x/wazuh-template.json
Wazuh module: https://packages.wazuh.com/4.x/filebeat/wazuh-filebeat-0.2.tar.gz
Here you can find our documentation for install and configuring of Filebeat: https://documentation.wazuh.com/current/installation-guide/wazuh-server/step-by-step.html#configuring-filebeat
On Aug 18, 2023, at 11:43 AM, 'Carlos Ezequiel Bordon' via Wazuh mailing list <wa...@googlegroups.com> wrote:
You received this message because you are subscribed to a topic in the Google Groups "Wazuh mailing list" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/CHvyl6Xv93A/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/f4d9c8cc-16ab-478c-a0a0-2c1f72e66cf5n%40googlegroups.com.
I could not give you an accurate answer, we have support for Filebeat 7.10.2.
As I mentioned earlier, you can try ingesting the Wazuh data into Graylog using another tool, such as Logstash.