Thank you for quick response.
I assumed my test logs were the right one since they are decoded and alerts are generated.
Here is log sample from archive.json
{"timestamp":"2022-09-20T12:32:16.417+0000","rule":{"level":4,"description":"OPNsense-FW [Parent Test Rule]","id":"176000","firedtimes":2,"mail":false,"groups":["OPNsense"]},"agent":{"id":"000","name":"wazuh-server"},"manager":{"name":"wazuh-server"},"id":"1663677136.728793","full_log":"Sep 20 12:31:21 OPNsense.localdomain dhclient[21400]: DHCPACK from 192.168.48.254","predecoder":{"program_name":"dhclient","timestamp":"Sep 20 12:31:21","hostname":"OPNsense.localdomain"},"decoder":{"name":"OPNsense-fw"},"data":{"FULL_LOG":"DHCPACK from 192.168.48.254"},"location":"192.168.48.250"}
It is decoded and alert is generated. But the way i worked around the decoder doesn't look to me like the right one
Here is my dashboard
