



--
You received this message because you are subscribed to a topic in the Google Groups "Wazuh mailing list" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/L-yz_vK1lGg/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/4ed8d2b9-71bc-433b-a40c-685fbee1d761n%40googlegroups.com.
![]() |
|
All the raw logs from Manager (/var/ossec/logs/archives/archives.json) will be auto archived by Wazuh and those (zips) need to be moved to AWS. *Only if logall is enabled.*
Index policies are specific to Indexers and Indices older than 90 days will be auto deleted with this policy.
Do I have an option not to delete these indices and compress those instead and move to AWS? Will it be of any use?
Or only raw logs at manager are enough to regenerate new indices?
--
You received this message because you are subscribed to a topic in the Google Groups "Wazuh mailing list" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/L-yz_vK1lGg/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/b7fc2e9d-37de-4d95-9891-1e250aa97fb7n%40googlegroups.com.
>> Hot/Warm/Cold Phase -- Is it a good practice to implement this? In few of the scenarios I read, each node is configured with different phase. I understood that hot would be ongoing, warm would be less used & cold would be least used. If it is advisable to configure this, could you please share KBs so that I can study this?
>> Enable archives -- Is it a good practice to implement this? Could you please help me share relevant KB to configure this?
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/1b348e47-bd99-4adb-81c0-d9b4084e5e43n%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/82e99d80-2447-494d-bbab-9f0fa4d484bbn%40googlegroups.com.
Hello Federico,
Thank you for your continuous support! I have started integrating the agents now.
I have observed following -
* After enabling logall_json, I could see two files getting created on both master and a worker which loooks identical in size and grows upto hundreds of gigs.
MASTER > `-rw-r——- 2 wazuh wazuh 3.6G Nov 25 11:33 /var/ossec/logs/archives/archives.json`
MASTER > `-rw-r——- 2 wazuh wazuh 3.6G Nov 25 11:33 /var/ossec/logs/archives/2022/Nov/ossec-archive-25.json`
WORKER > `-rw-r——- 2 wazuh wazuh 1.6G Nov 25 11:40 /var/ossec/logs/archives/archives.json`
WORKER > `-rw-r——- 2 wazuh wazuh 1.6G Nov 25 11:40 /var/ossec/logs/archives/2022/Nov/ossec-archive-25.json`
Is it creating two duplicate files? Is it a normal behavior?
* Compared to wazuh-manager, when checked on wazuh-indexers, I was shocked as hardly any space getting consumed (few hundred MBs). Will it grow later post data processing?
Regards,
swapnils
MASTER > `-rw-r——- 2 wazuh wazuh 3.6G Nov 25 11:33 /var/ossec/logs/archives/archives.json`
MASTER > `-rw-r——- 2 wazuh wazuh 3.6G Nov 25 11:33 /var/ossec/logs/archives/2022/Nov/ossec-archive-25.json`
WORKER > `-rw-r——- 2 wazuh wazuh 1.6G Nov 25 11:40 /var/ossec/logs/archives/archives.json`WORKER > `-rw-r——- 2 wazuh wazuh 1.6G Nov 25 11:40 /var/ossec/logs/archives/2022/Nov/ossec-archive-25.json`
Is it creating two duplicate files? Is it a normal behavior?
* Compared to wazuh-manager, when checked on wazuh-indexers, I was shocked as hardly any space getting consumed (few hundred MBs). Will it grow later post data processing?
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/9ba02b5e-c1ce-496a-be54-78445d366cddn%40googlegroups.com.