root@wazuh:/var/ossec/etc/decoders# /var/ossec/bin/wazuh-logtest
Starting wazuh-logtest v4.11.2
Type one log per line
May 14 11:55:12 UDM-DATACENTER [LOCAL_LAN-A-2147483647] DESCR=\"[LOCAL_LAN]Allow All Traffic\" IN= OUT=br102 MAC= SRC=172.16.102.10 DST=172.16.102.198 LEN=52 TOS=00 PREC=0x00 TTL=64 ID=28634 DF PROTO=TCP SPT=7550 DPT=54452 SEQ=1325727731 ACK=2021585811 WINDOW=32746 ACK URGP=0 UID=982 GID=981 MARK=1c0000
**Phase 1: Completed pre-decoding.
full event: 'May 14 11:55:12 UDM-DATACENTER [LOCAL_LAN-A-2147483647] DESCR=\"[LOCAL_LAN]Allow All Traffic\" IN= OUT=br102 MAC= SRC=172.16.102.10 DST=172.16.102.198 LEN=52 TOS=00 PREC=0x00 TTL=64 ID=28634 DF PROTO=TCP SPT=7550 DPT=54452 SEQ=1325727731 ACK=2021585811 WINDOW=32746 ACK URGP=0 UID=982 GID=981 MARK=1c0000'
timestamp: 'May 14 11:55:12'
hostname: 'UDM-DATACENTER'
**Phase 2: Completed decoding.
name: 'allow_all_traffic'
The only change on local_decoder.xml is this entry:
<decoder name="allow_all_traffic">
<prematch>Allow\sAll\sTraffic</prematch>
</decoder>
Any other entry I try to create makes logtest not to complete phase 2.
These are other two types of logs that I see on archives.json:
{"timestamp":"2025-05-15T17:32:06.838+0000","agent":{"id":"000","name":"wazuh"},"manager":{"name":"wazuh"},"id":"1747330326.127624015","full_log":"May 15 14:32:06 UDM-DATACENTER [WAN_LAN-D-10004] DESCR=\"Bloqueia tudo \" IN=eth9 OUT=br103 MAC=28:70:4e:45:89:42:b0:be:76:ab:69:5d:08:00 SRC=192.168.10.87 DST=172.16.103.159 LEN=52 TOS=00 PREC=0x00 TTL=126 ID=61229 DF PROTO=TCP SPT=54375 DPT=7680 SEQ=3551523209 ACK=0 WINDOW=64240 SYN URGP=0 MARK=1c0000 ","predecoder":{"timestamp":"May 15 14:32:06","hostname":"UDM-DATACENTER"},"decoder":{},"location":"172.16.103.10"}
{"timestamp":"2025-05-15T17:54:39.411+0000","agent":{"id":"000","name":"wazuh"},"manager":{"name":"wazuh"},"id":"1747331679.130729773","full_log":"May 15 14:54:39 UDM-DATACENTER CEF:0|Ubiquiti|UniFi Network|9.1.120|Firewall|Blocked by Firewall|4|msg=192.168.30.198 was blocked from accessing 172.16.101.92 by Bloqueia tudo .","predecoder":{"program_name":"CEF","timestamp":"May 15 14:54:39","hostname":"UDM-DATACENTER"},"decoder":{},"location":"172.16.103.10"}
Any help will be appreciated.
Thanks.