Hi everyone,
I’m trying to drop certain syslog events that are being sent to port 514 on my Wazuh manager, based on specific patterns or regex matches. I’ve looked through the Wazuh documentation but haven’t found any options within the Wazuh remote module to filter or discard events at this stage.
My goal is to drop these events before they reach the Wazuh manager (not at the filebeat or logstash level).
Thanks in advance for your support.
Thanks!