Hi Team,
I had a little difficulty in troubleshooting in viewing alerts on my centralized wazuh serverA. I had connected two wazuh servers together by wazuh api. Im able to view alerts of serverA(which I use it as my centralized wazuh server) but not able to view alerts of other connected Client wazuh server. I have two wazuh servers and wants to view the alerts of both servers into single dashboard. I have elastic stack installed on my both wazuh servers having version 4.4.1 running on ubuntu. I tried to achieve this by refereeing the below wazuh guide to achieve my objective of connecting multiple wazuh servers of my clients to my centralized wazuh server where I can view their alerts on wazuh dashboard without storing client server alerts on my master server.
I have configured API configuration on both servers. In both servers they are connected fine, but still whenever I switch API from master to clientA. It does not show any alerts. Please find the screenshots of my API configuration.
The first screenshot is of my master wazuh server and second was my testing client wazuh server.
Note: Both of my wazuh servers are installed as All-in-one deployment.
https://documentation.wazuh.com/current/user-manual/wazuh-dashboard/config-file.html#hosts
Master Server:

ClientA Server:

Looking forward for you response.
Thanks & Regards,
Muhammad Hassam
SOC Analyst | Information Security Department
Arpatech
195 Block A SMCHS,
Karachi, PAKISTAN
Ph: +92-21-35250741-6
Web: www.arpatech.com
Hi Kasim,
Thanks for the consideration. I’m looking forward for your response.
Thanks & Regards,
Muhammad Hassam
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/fd34641d-edc0-4791-ac6e-765e6bc42023n%40googlegroups.com.
Hi Team & kasim,
Your kind response is awaited.
Thanks,
| Kasim Mustapha IT Security Engineer The Open Source Security Platform |
Hi Kasim,
Yes, my objective is to view the alerts of multiple Wazuh server instances into single kibana dashboard so that I don’t need to switch to each Wazuh server instance to view their alerts. I need a centralized configuration where I can view them from my master Wazuh server dashboard.
Furthermore, in master server, I want to store the alerts of only master server alerts but no alerts of other server. So that my master server won’t get storage issue.
I was trying to achieve this objective by connecting each server API into master server but still not able to properly figure out the issue as I described earlier. If it is possible then kindly guide me the approach to achieve this objective.
Looking forward for your response.
Thanks,
Hi kasim,
Waiting for your kind response.