Hi at all..
I have maked some test, and have understand it: with SonicOS SonicOS Enhanced 6.5.3.1-48n something not work.
After about 15 days (i'm busy with other work) I can say this: with SonicOS 5.9 all work fine and I see log on 'kibana->discovery' but with SonicOS 6.5 not even see event.
Should this event be registered by wazuh or not? In my opinion, yes..
[root@tech2srv31 ~]# tcpdump -i eth0 host 10.12.14.1 -n -A
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes
12:55:40.574953 IP 10.12.14.1.syslog > 10.12.14.31.syslog: SYSLOG local0.notice, length: 283
E..7.0@.@.!N
...
........#p.<133> id=NSA3600 sn=C0EAE4599999 time="2019-02-27 12:55:40 UTC" fw=2.228.169.242 pri=5 c=0 m=1197 msg="NAT Mapping" n=4748427 src=10.12.14.9::X0-V500 dst=217.56.236.4::X3 proto=icmp note="Source: 2.228.169.242, 63130, Destination: 217.56.236.4, 8, Protocol: 1" rule="17 (LAN->WAN)"
^C
1 packet captured
10 packets received by filter
0 packets dropped by kernel
[root@tech2srv31 ~]# /var/ossec/bin/ossec-logtest
2019/02/27 12:55:48 ossec-testrule: INFO: Started (pid: 11529).