Also setup rsyslog to write logs entries on fortigate.log file. Is rsyslog setup nedeed or <remote> config must be especified too? A simple record in alert.json is as
{"timestamp":"2025-12-02T02:49:30.040+0100","rule":{"level":6,"description":"Fortigate: Blocked URL belongs to a denied category in policy.","id":"81644","firedtimes":2773,"mail":false,"groups":["fortigate","syslog"]},"agent":{"id":"000","name":"debian13-Trixie"},"manager":{"name":"debian13-Trixie"},"id":"1764640170.38373798","cluster":{"name":"wazuh","node":"nodeHRC"},"full_log":"2025-12-02T02:49:28.561381+01:00 10.5.0.253 date=2025-12-01 time=20:49:28 devname=\"XXX-FW\" devid=\"FG100ETK\" eventtime=1764640167994287978 tz=\"-0500\" logid=\"0316013056\" type=\"utm\" subtype=\"webfilter\" eventtype=\"ftgd_blk\" level=\"warning\" vd=\"root\" policyid=33 poluuid=\"24dac426-9c1c-51ed-0368-ef6571186f00\" policytype=\"policy\" sessionid=71583697 srcip=10.60.2.85 srcport=57804 srccountry=\"Reserved\" srcintf=\"port1\" srcintfrole=\"lan\" srcuuid=\"0d2dc6e6-8ef3-51e9-cf51-866bb8df0219\" dstip=20.190.155.130 dstport=443 dstcountry=\"United States\" dstintf=\"port4\" dstintfrole=\"wan\" dstuuid=\"8c1145be-b2ad-51e8-4591-ea981bd4ad00\" proto=6 service=\"HTTPS\" hostname=\"
login.live.com\" profile=\"WF-Restrictable\" action=\"blocked\" reqtype=\"direct\" url=\"
https://login.live.com/\" sentbyte=229 rcvdbyte=0 direction=\"outgoing\" msg=\"URL belongs to a denied category in policy\" method=\"domain\" cat=41 catdesc=\"Máquinas de búsqueda y Portales\"","predecoder":{"timestamp":"2025-12-02T02:49:28.561381+01:00"},"decoder":{"name":"fortigate-firewall-v5"},"data":{"action":"blocked","srcip":"10.60.2.85","srcport":"57804","dstip":"20.190.155.130","dstport":"443","url":"
https://login.live.com/","devid":"FG100ETK","devname":"XXX-FW","direction":"outgoing","dstcountry":"United States","dstintf":"port4","dstintfrole":"wan","eventtime":"1764640167994287978","eventtype":"ftgd_blk","hostname":"
login.live.com","level":"warning","logid":"0316013056","msg":"URL belongs to a denied category in policy","policyid":"33","poluuid":"24dac426-9c1c-51ed-0368-ef6571186f00","profile":"WF-Restrictable Bares y Rest","proto":"6","rcvdbyte":"0","reqtype":"direct","sentbyte":"229","service":"HTTPS","sessionid":"71583697","srccountry":"Reserved","srcintf":"port1","srcintfrole":"lan","subtype":"webfilter","time":"20:49:28","type":"utm","vd":"root"},"location":"/var/log/fortigate.log"}
I'm a bit confused rigth now, in manager dashboard there aren't any alert from worker. Seems to be trouble in redirecting alerts, but new agents is rolling up from that worker.
Thanks in advance.