Hi everyone,
My Wazuh managers and indexers are running on separate instances, and I store all logs on the indexer nodes. However, I’ve noticed that some alerts and archive logs are also being stored on the manager nodes (see photo).
I don’t want to keep these logs on the managers, as they consume significant storage. I only want to retain the most recent logs on the manager nodes. The bulk of the logs should be stored on the indexers, where sufficient storage is available.
How can I solve this problem?
