I'm new to wazuh, so my questions may seem funny to you :) Archive logs are permanent and can record as much as the disk space on the server. However, Alert records are analyzed from the logs in the archives and displayed as a result of certain rules. And when the alert logs are not cleared, I think the indexing is full and cannot receive new logs. Therefore, it is necessary to clear alert logs at certain periods (which is completely related to our structure). But as I said before, archive logs are stored until the disk space is full.
Could you please confirm if my thoughts and experiences above are correct?
3 Haziran 2024 Pazartesi tarihinde saat 20:07:03 UTC+3 itibarıyla Eli Josue Rodriguez şunları yazdı: