Hi, it is not clear to me the architecture you have. Could you elaborate it and be more explicit in the elements/applications you are mentioning? A diagram could be useful.
Please, elaborate your architecture and want to get with Logstash or the Wazuh agents (I am not sure if you are referring to this or another type of agent).
I guess you want to add Logstash to read, transform and send the Wazuh alerts data (generated by the Wazuh managers) to other outputs or same Wazuh indexer for some reason.
I have clone my current system and configure the setup, but i want to have the same agent for the testing since they have a constant stream of log and is better for testing, is there a way to send log to different wazuh server master node at the same time ?
This comment is not clear to me:
- What system did you clone and configure the setup?
- What are you referring by same agent?
- Do you have 2 separate Wazuh stack environments (production and testing) and you want to use the same Wazuh agent that report data to different Wazuh managers? If this is the case, it is not possible.
If you are referring to a Wazuh agent, this only can send data to a Wazuh manager at the same time.