/var/ossec/etc/ossec.conf
<remote> <connection>syslog</connection> <allowed-ips>syslog ip</allowed-ips> </remote>
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/639c6c69-1693-48d7-acbe-cab11cd2165f%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
Hi,the Wazuh manager receives logs from syslog.You will probably need to specify the port where you expect the logs frow as well as the protocol (udp, tcp).This is our documentation for the remote tag: https://documentation.wazuh.com/3.x/user-manual/reference/ossec-conf/remote.htmlBest regards.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/60741909-5ff3-4ee8-8551-b960e2ccd18d%40googlegroups.com.
tcpdump -vv -x -X -s 1500 -i enp0s3 'port 514'
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/a5ae3f3c-387e-4983-a510-24ee683dcbb8%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/745343d5-e7d3-4e64-9d01-8d60db2109a1%40googlegroups.com.
My bad.
You have to enable the logall_json option in the manager so that file gets populated.Edit the file /var/ossec/etc/ossec.conf.You will find one block like this at the beginning:
<global><jsonout_output>yes</jsonout_output><alerts_log>yes</alerts_log><logall>no</logall><logall_json>no</logall_json><email_notification>no</email_notification><smtp_server>smtp.example.wazuh.com</smtp_server>
<email_from>ossecm@example.wazuh.com</email_from><email_to>recipient@example.wazuh.com</email_to>
<email_maxperhour>12</email_maxperhour><queue_size>131072</queue_size></global>
Change the setting logall_json from 'no' to 'yes' and restart the Wazuh manager.This will populate the archives.json file and then you can search in there looking for your syslog logs.If you can't find them after doing that, then it means the Wazuh manager is not reading those logs and the problem must be in another place.Best regards.
netstat -tunap | grep :514tcpdump -i any port 514 -AA........'_v.....E..F..@.@.#...G...G..@...2..<187>Feb 14 08:31:23 agent programname: test................echo "Feb 14 08:31:23 agent programname: test" | /var/ossec/bin/ossec-logtest