Hi,
Thanks for your answer !
So, i read your docs, and I configured syslog listener on wazuh server and the rsyslog on a virtual machine. But, about the /etc/rsyslog.conf :
if $fromhost-ip startswith '<YOUR_MIKROTIK_IP_ADDRESS>' then /var/log/mikrotik.log
If I understood well, I must replace 'Your Mirotik IP Address" by my checkpoint address, but my checkpoint is on cloud. How can I do to do it so ?
I'm begining in IT and Wazuh, sorry for having questions wich can be stupids....
Thanks in advance !