Hi Kris Springer,
Thank you for using wazuh and sharing your question with the community. Wazuh has a functionality that allows you to get the output command with a custom rule if you create it. I'll share you the
link that explains how it works. Please, you should follow these steps to use the feature:
- Set the logcollector.remote_command flag to 1 in local_internal_options.conf file.
- Add the localfile section in ossec.conf or
agent.conf depending on whether you want to share the configuration with
a group of agents or configure it for a specific agent.
- Create a rule to receive the alert in the manager.
I send you the
link to the documentation of the configuration, there are interesting examples about command monitoring.
I hope that this information will be useful for your purpose.
Best regards
Hanes