Hello Costantino,
Thanks for reaching out.
You're getting the error because you're not supposed to update the Wazuh manager's
/var/ossec/etc/ossec.conf file with your decoders. Since you're creating a custom decoder, you can configure your decoder in the file
/var/ossec/etc/decoders/local_decoder.xml or you can do your configuration on the dashboard too which also enables you to test your decoders as you configure and finetune them.
- On your dashboard, go to Management => Decoder and click Custom decoders.
- Click on the local_decoder.xml , configure your decoders, save them and also test them accordingly to be sure they meet your need (screenshot attached).
I'd also be attaching some useful links below for your perusal:
I hope this helps. If you have any other query, do not hesitate to ask.
Best Regards.