--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/CACW3duC7bFnj%2BwOX-Pu2qViVpLjFpXKkCrWG3GCoQehHrYAfLg%40mail.gmail.com.
After going through some blogs, I understood, we need to forward the Audit logs to Wazuh using Syslog.
<remote> <connection>syslog</connection> <port>514</port>
<protocol>udp</protocol> <allowed-ips>0.0.0.0/0</allowed-ips> </remote>I believe you need to write the decoder if those are not in JSON format. Recent version have recently started supporting JSON format.
On Tue, Sep 17, 2019 at 12:26 PM Aravind Krishnan <krishnan...@gmail.com> wrote:
Hello--I have requirement to parse Cylance audit logs in Wazuh and it's been shown in Elastic search.After going through some blogs, I understood, we need to forward the Audit logs to Wazuh using Syslog.What are the configurations needed in Wazuh for processing the Cylance logs?--Regards,
Aravind Krishnan
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/CACW3duC7bFnj%2BwOX-Pu2qViVpLjFpXKkCrWG3GCoQehHrYAfLg%40mail.gmail.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/5ec4f9c7-864c-44b3-824a-d2c81b4c064e%40googlegroups.com.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/CACW3duC7bFnj%2BwOX-Pu2qViVpLjFpXKkCrWG3GCoQehHrYAfLg%40mail.gmail.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/5ec4f9c7-864c-44b3-824a-d2c81b4c064e%40googlegroups.com.
--Regards,
Aravind Krishnan