<localfile>
<log_format>syslog</log_format>
<location>/var/log/mongodb/mongodb.log</location>
</localfile>
systemctl restart wazuh-agenttail -f tail -f /var/ossec/logs/archives/archives.log | grep "/var/log/mongodb/mongodb.log"echo "2020-10-27T11:30:03.198+0530 I NETWORK [listener] connection accepted from 127.0.0.1:36556 #1 (1 connection now open)" >> /var/log/mongodb/mongodb.log2020 Oct 28 11:39:13 (centos8_agent) any->/var/log/mongodb/mongodb.log 2020-10-27T11:30:03.198+0530 I NETWORK [listener] connection accepted from 127.0.0.1:36556 #1 (1 connection now open) <localfile>
<log_format>syslog</log_format>
<location>/var/log/mongodb/mongodb.log</location>
<out_format>$(timestamp) $(hostname) mongodb: $(log)</out_format>
</localfile>systemctl restart wazuh-agenttail -f tail -f /var/ossec/logs/archives/archives.log | grep "/var/log/mongodb/mongodb.log"echo "2020-10-27T11:30:03.198+0530 I NETWORK [listener] connection accepted from 127.0.0.1:36556 #1 (1 connection now open)" >> /var/log/mongodb/mongodb.log2020 Oct 28 11:40:58 (centos8_agent) any->/home/vagrant/test/test.log Oct 28 07:40:58 agent1 mongodb: 2020-10-27T11:30:03.198+0530 I NETWORK [listener] connection accepted from 127.0.0.1:36556 #1 (1 connection now open)[root@manager]# /var/ossec/bin/ossec-logtest
2020/10/28 11:32:53 ossec-testrule: INFO: Started (pid: 7091).
ossec-testrule: Type one log per line.
Oct 28 07:40:58 agent1 mongodb: 2020-10-27T11:30:03.198+0530 I NETWORK [listener] connection accepted from 127.0.0.1:36556 #1 (1 connection now open)
**Phase 1: Completed pre-decoding.
full event: 'Oct 28 07:40:58 agent1 mongodb: 2020-10-27T11:30:03.198+0530 I NETWORK [listener] connection accepted from 127.0.0.1:36556 #1 (1 connection now open)'
timestamp: 'Oct 28 07:40:58'
hostname: 'agent1'
program_name: 'mongodb'
log: '2020-10-27T11:30:03.198+0530 I NETWORK [listener] connection accepted from 127.0.0.1:36556 #1 (1 connection now open)'
**Phase 2: Completed decoding.
No decoder matched.