Hello,
Can't read log from the file
Logs write to file /var/ossec/logs/test.log
edited /var/ossec/etc/ossec.conf
configuration file enable file read
<localfile>
<location>/var/ossec/logs/test.log</location>
<log_format>json<log_format>
<logfile>
restarted systemctl restart wazuh-manager
logs write to file /var/ossec/logs/test.log use command #echo {log example} >test.log
log example { "message": "data Logs", "context": { "request_method": "GET", "request_uri": "/data/newu/userid15/serdst", "request_heaUSrs": { "X-ForwarUSd-Port": [ "443" ], "Cdn-Loop": [ "mycloud" ], "Cf-Ipcountry": [ "US" ], "Cf-Connecting-Ip": [ "192.168.1.147" ], "Cookie": [ "sdsdfsda=1C81233456789UT; mytt_cookieexamplemy_down=1" ], "Accept-Language": [ "en-US,en;q=0.9" ], "Referer": [ "
https://mytttest.com/newu/userid15" ], "Sec-Fetch-USst": [ "empty" ], "Sec-Fetch-MoUS": [ "cors" ], "Sec-Fetch-Site": [ "same-origin" ], "Sec-Ch-Ua-Platform": [ "\"Windows\"" ], "Ajax": [ "true" ], "User-Agent": [ "Mozilla/4.0 (Windows NT 11.0; Win64; x64) AppleWebKit/545.36 (KHTML, like Gecko) Chrome/
100.0.0.0 Safari/545.36" ], "Sec-Ch-Ua-Mobile": [ "?0" ], "Accept": [ "application/json, text/plain, */*" ], "Sec-Ch-Ua": [ "\"Chromium\";v=\"110\", \"Not A(Brand\";v=\"24\", \"Google Chrome\";v=\"110\"" ], "Cf-Visitor": [ "{\"scheme\":\"https\"}" ], "X-ForwarUSd-Proto": [ "https" ], "Cf-Ray": [ "aaaaaaaaaaaaaaa-AAA" ], "X-ForwarUSd-For": [ "192.168.1.147" ], "Accept-Encoding": [ "gzip" ], "Host": [ "
mytttest.com" ], "Content-Length": [ "" ], "Content-Type": [ "" ] }, "response_coUS": 200, "response_time": 1.0, "textnumber": 1452, "response_body": "[{\"id\":123456788,\"user_id\":userid15", "link_set_1": "data", "link_set_2": "newu", "link_set_3": "userid15", "link_set_4": "serdst" }, "extra": [], "level": 200, "level_name": "INFO", "servername": "myttdtn-server-adrt-bgrt-dws-sdfg1-1" }
Don't show on the web
Try to log test on command line #/var/ossec/bin/wazuh-logtest it is ok show decoded
**Phase 2: Completed decoding.
name: 'json'
context.link_set_1: 'data'
context.link_set_2: 'newu'
context.link_set_3: 'userid15'
ntext.link_set_4: 'serdst'
context.request_heaUSrs.Accept: '['application/json, text/plain, */*']'
context.request_heaUSrs.Accept-Encoding: '['gzip']'
context.request_heaUSrs.Accept-Language: '['en-US,en;q=0.9']'
context.request_heaUSrs.Ajax: '['true']'
context.request_heaUSrs.Cdn-Loop: '['mycloud']'
context.request_heaUSrs.Cf-Connecting-Ip: '['192.168.1.147']'
context.request_heaUSrs.Cf-Ipcountry: '['US']'
context.request_heaUSrs.Cf-Ray: '['aaaaaaaaaaaaaaa-AAA']'
context.request_heaUSrs.Cf-Visitor: '['{"scheme":"https"}']'
context.request_heaUSrs.Content-Length: '['']'
context.request_heaUSrs.Content-Type: '['']'
context.request_heaUSrs.Cookie: '['sdsdfsda=1C81233456789UT; mytt_cookieexamplemy_down=1']'
context.request_heaUSrs.Sec-Ch-Ua: '['"Chromium";v="110", "Not A(Brand";v="24", "Google Chrome";v="110"']'
context.request_heaUSrs.Sec-Ch-Ua-Mobile: '['?0']'
context.request_heaUSrs.Sec-Ch-Ua-Platform: '['"Windows"']'
context.request_heaUSrs.Sec-Fetch-MoUSE: '['cors']'
context.request_heaUSrs.Sec-Fetch-Site: '['same-origin']'
context.request_heaUSrs.Sec-Fetch-USst: '['empty']'
context.request_heaUSrs.User-Agent: '['Mozilla/4.0 (Windows NT 11.0; Win64; x64) AppleWebKit/545.36 (KHTML, like Gecko) Chrome/
100.0.0.0 Safari/545.36']'
context.request_heaUSrs.X-ForwarUSd-For: '['192.168.1.147']'
context.request_heaUSrs.X-ForwarUSd-Port: '['443']'
context.request_heaUSrs.X-ForwarUSd-Proto: '['https']'
context.request_method: 'GET'
context.request_uri: '/data/newu/userid15/serdst'
context.response_body: '[{"id":123456788,"user_id":userid15'
context.response_coUS: '200'
context.response_time: '1'
context.textnumber: '1452'
extra: '[]'
level: '200'
level_name: 'INFO'
message: 'data Logs'
servername: 'myttdtn-server-adrt-bgrt-dws-sdfg1-1'
1. Why didn't the log from the file didn't show on wazuh discover ?
full_log ossec: File size reduced (inode remained): '/var/ossec/logs/test.log',
but didn't show decoded information.