I feel this issue has succumb to the irresistible force of IT magic where the mere mention of the issue followed by acknowledgment by a professional is enough to correct the issue.
I woke up this morning to find a new index had been created and it appears logs are being written to the indexers, again.
Further, per your request, here is the filebeat output:
root@wazuhmanager-0:~# systemctl status filebeat.service
● filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch.
Loaded: loaded (/lib/systemd/system/filebeat.service; enabled; preset: enabled)
Active: active (running) since Tue 2025-04-22 14:57:14 UTC; 2s ago
Docs:
https://www.elastic.co/products/beats/filebeat Main PID: 233745 (filebeat)
Tasks: 13 (limit: 153736)
Memory: 20.9M
CPU: 125ms
CGroup: /system.slice/filebeat.service
└─233745 /usr/share/filebeat/bin/filebeat --environment systemd -c /etc/filebeat/filebeat.yml --path.home /usr/share/filebeat ->
Apr 22 14:57:14 wazuhmanager-0 systemd[1]: Started filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch..
root@wazuhmanager-0:~# tail -f /var/log/filebeat/filebeat
2025-04-22T14:57:16.197Z
INFO
[index-management]
idxmgmt/std.go:298
Loaded index template.
2025-04-22T14:57:16.200Z
INFO
[publisher_pipeline_output]
pipeline/output.go:151
Connection to backoff(elasticsearch(
https://192.168.88.4:9200)) established
2025-04-22T14:57:16.201Z
INFO
[esclientleg]
eslegclient/connection.go:314
Attempting to connect to Elasticsearch version 7.10.2
2025-04-22T14:57:16.203Z
INFO
template/load.go:97
Template wazuh already exists and will not be overwritten.
2025-04-22T14:57:16.203Z
INFO
[index-management]
idxmgmt/std.go:298
Loaded index template.
2025-04-22T14:57:16.206Z
INFO
[publisher_pipeline_output]
pipeline/output.go:151
Connection to backoff(elasticsearch(
https://192.168.88.8:9200)) established
2025-04-22T14:57:16.207Z
INFO
[esclientleg]
eslegclient/connection.go:314
Attempting to connect to Elasticsearch version 7.10.2
2025-04-22T14:57:16.208Z
INFO
template/load.go:97
Template wazuh already exists and will not be overwritten.
2025-04-22T14:57:16.209Z
INFO
[index-management]
idxmgmt/std.go:298
Loaded index template.
2025-04-22T14:57:16.212Z
INFO
[publisher_pipeline_output]
pipeline/output.go:151
Connection to backoff(elasticsearch(
https://192.168.88.2:9200)) established
That said, the number of alerts I am receiving seems suspiciously low. How would I verify whether any specific agent is having issues communicating or whether any alerts are being dropped rather than written?