
Hi,
I tested the log (full_log), and it matches the default Windows date format decoder. However, it does not match any rule.
I also created a custom decoder like the following:
<decoder name="manage-engine-access-api">This decoder works correctly in my test environment, as shown in the attached image.
To identify the cause of the issue in your setup, please share the following information:
The decoder configuration you created.
The related log from archives.json.
You can extract the log using the following command:
cat /var/ossec/logs/archives/archives.json| grep <part_of_the_log>Please make sure to hide any sensitive information before sharing the logs.
Also, to learn more about decoders, please refer to https://documentation.wazuh.com/current/user-manual/ruleset/decoders/index.html
--
You received this message because you are subscribed to a topic in the Google Groups "Wazuh | Mailing List" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/vGYThjMhL7c/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/wazuh/c857a780-f498-4023-9a85-ffa53c15dfe1n%40googlegroups.com.