Hi,
If you remove the preceding
<191>, then the log is recognized as a Cisco IOS debug message.
[root@wz41-mngr bin]#
./ossec-logtest2021/04/30 14:06:16 ossec-testrule: INFO: Started (pid: 4599).
Since Wazuh v4.1.0 this binary is deprecated. Use wazuh-logtest instead
ossec-testrule: Type one log per line.
143: %SYS-7-USERLOG_DEBUG: Message from tty1(user id: XXXXX): testtesttest'**Phase 1: Completed pre-decoding.
full event: '143: %SYS-7-USERLOG_DEBUG: Message from tty1(user id: XXXXX): testtesttest''
timestamp: '(null)'
hostname: 'wz41-mngr'
program_name: '(null)'
log: '143: %SYS-7-USERLOG_DEBUG: Message from tty1(user id: XXXXX): testtesttest''
**Phase 2: Completed decoding.
decoder: 'cisco-ios'
id: '%SYS-7-USERLOG_DEBUG'
**Phase 3: Completed filtering (rules).
Rule id: '
4717'
Level: '0'
Description: '
Cisco IOS debug message.'