Hello Community,
I am facing an issue related to historical Wazuh archives/alerts that were not indexed due to the limit of shard in each node.
Context:
Wazuh Manager was running and generating logs correctly.
Alerts are present on disk : /var/ossec/logs/alerts/2025/Dec/ossec-alerts-*.json
Current situation:
I would like to ingest or reindex these historical .json alert files so they appear correctly in Wazuh Dashboard.
Any guidance, documentation, or best practices would be greatly appreciated.
Thank you in advance for your help.
Best regards,