Hi Mario,
I have checked the threads from you above, but it seem like not my problem.
With the Fortinet logs I have send, my wazuh just display one alert and it is rule id
81619.
The alert in image.
Although my alert logs are different from each other, but i don't know why there is just one alert.
I have checked the archives.log and see everything is normally:
2023 May 22 08:43:27 dc-siemtest->10.33.5.6 logver=604061879 timestamp=1684719866 tz="UTC+7" devname="FortiGate_HA_FGT2KE" devid="FGT2KETB19900273" vd="root" date=2023-05-22 time=08:44:26 eventtime=1684719866451753252 tz="+0700" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=10.33.137.144 srcport=53325 srcintf="Vlan_4" srcintfrole="lan" dstip=10.33.5.62 dstport=53 dstintf="Vlan_51" dstintfrole="lan" srccountry="Reserved" dstcountry="Reserved" sessionid=1887373928 proto=17 action="accept" policyid=126 policytype="policy" poluuid="1bf99d44-0c07-51ea-6e7b-0bb9781e5fc2" policyname="AD2" service="TCP_UDP_53" trandisp="noop" duration=97 sentbyte=234 rcvdbyte=78 sentpkt=3 rcvdpkt=1 appcat="unscanned" mastersrcmac="40:06:d5:2a:4f:d7" srcmac="40:06:d5:2a:4f:d7" srcserver=0 dsthwvendor="VMware" masterdstmac="00:50:56:93:9b:10" dstmac="00:50:56:93:9b:10" dstserver=1
2023 May 22 08:43:27 dc-siemtest->10.33.5.6 logver=604061879 timestamp=1684719866 tz="UTC+7" devname="FortiGate_HA_FGT2KE" devid="FGT2KETB19900273" vd="root" date=2023-05-22 time=08:44:26 eventtime=1684719866621743440 tz="+0700" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=10.33.5.141 srcport=64839 srcintf="Vlan_53" srcintfrole="lan" dstip=10.81.161.201 dstport=80 dstintf="Vlan_4" dstintfrole="lan" srccountry="Reserved" dstcountry="Reserved" sessionid=1887447008 proto=6 action="timeout" policyid=176 policytype="policy" poluuid="1c6f260c-c659-51e9-64ff-90c68a11bc67" policyname="Permit-ALL" service="HTTP" trandisp="noop" duration=8 sentbyte=44 rcvdbyte=0 sentpkt=1 rcvdpkt=0 appcat="unscanned" masterdstmac="40:06:d5:2a:4f:d7" dstmac="40:06:d5:2a:4f:d7" dstserver=0
2023 May 22 08:43:27 dc-siemtest->10.33.5.6 logver=604061879 timestamp=1684719866 tz="UTC+7" devname="FortiGate_HA_FGT2KE" devid="FGT2KETB19900273" vd="root" date=2023-05-22 time=08:44:26 eventtime=1684719866491746978 tz="+0700" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=10.33.6.35 srcport=34560 srcintf="Vlan_4" srcintfrole="lan" dstip=10.33.5.77 dstport=444 dstintf="Vlan_52" dstintfrole="lan" srccountry="Reserved" dstcountry="Reserved" sessionid=1887449416 proto=6 action="server-rst" policyid=382 policytype="policy" poluuid="2d99ce7c-afff-51ec-5862-0a5d00d2d330" policyname="DR-AD" service="tcp/444" trandisp="noop" duration=5 sentbyte=449 rcvdbyte=313 sentpkt=5 rcvdpkt=4 appcat="unscanned" mastersrcmac="40:06:d5:2a:4f:d7" srcmac="40:06:d5:2a:4f:d7" srcserver=0 dsthwvendor="VMware" dstosname="Windows" dstswversion="8" dstunauthuser="thuy-th" dstunauthusersource="kerberos" masterdstmac="00:50:56:93:22:ee" dstmac="00:50:56:93:22:ee" dstserver=0
2023 May 22 08:43:27 dc-siemtest->10.33.5.6 logver=604061879 timestamp=1684719866 tz="UTC+7" devname="FortiGate_HA_FGT2KE" devid="FGT2KETB19900273" vd="root" date=2023-05-22 time=08:44:26 eventtime=1684719866561745933 tz="+0700" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=10.33.6.35 srcport=34571 srcintf="Vlan_4" srcintfrole="lan" dstip=10.33.5.78 dstport=444 dstintf="Vlan_52" dstintfrole="lan" srccountry="Reserved" dstcountry="Reserved" sessionid=1887449446 proto=6 action="server-rst" policyid=382 policytype="policy" poluuid="2d99ce7c-afff-51ec-5862-0a5d00d2d330" policyname="DR-AD" service="tcp/444" trandisp="noop" duration=5 sentbyte=449 rcvdbyte=313 sentpkt=5 rcvdpkt=4 appcat="unscanned" mastersrcmac="40:06:d5:2a:4f:d7" srcmac="40:06:d5:2a:4f:d7" srcserver=0 dsthwvendor="VMware" dstosname="Windows" dstswversion="8" dstunauthuser="administrator" dstunauthusersource="kerberos" masterdstmac="00:50:56:93:a7:a2" dstmac="00:50:56:93:a7:a2" dstserver=0
2023 May 22 08:43:27 dc-siemtest->10.33.5.6 logver=604061879 timestamp=1684719866 tz="UTC+7" devname="FortiGate_HA_FGT2KE" devid="FGT2KETB19900273" vd="root" date=2023-05-22 time=08:44:26 eventtime=1684719866511746704 tz="+0700" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=10.33.6.35 srcport=34566 srcintf="Vlan_4" srcintfrole="lan" dstip=10.33.5.77 dstport=444 dstintf="Vlan_52" dstintfrole="lan" srccountry="Reserved" dstcountry="Reserved" sessionid=1887449434 proto=6 action="server-rst" policyid=382 policytype="policy" poluuid="2d99ce7c-afff-51ec-5862-0a5d00d2d330" policyname="DR-AD" service="tcp/444" trandisp="noop" duration=5 sentbyte=449 rcvdbyte=313 sentpkt=5 rcvdpkt=4 appcat="unscanned" mastersrcmac="40:06:d5:2a:4f:d7" srcmac="40:06:d5:2a:4f:d7" srcserver=0 dsthwvendor="VMware" dstosname="Windows" dstswversion="8" dstunauthuser="thuy-th" dstunauthusersource="kerberos" masterdstmac="00:50:56:93:22:ee" dstmac="00:50:56:93:22:ee" dstserver=0
2023 May 22 08:43:27 dc-siemtest->10.33.5.6 logver=604061879 timestamp=1684719866 tz="UTC+7" devname="FortiGate_HA_FGT2KE" devid="FGT2KETB19900273" vd="root" date=2023-05-22 time=08:44:26 eventtime=1684719866581748960 tz="+0700" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=10.33.6.35 srcport=34585 srcintf="Vlan_4" srcintfrole="lan" dstip=10.33.5.78 dstport=444 dstintf="Vlan_52" dstintfrole="lan" srccountry="Reserved" dstcountry="Reserved" sessionid=1887449470 proto=6 action="server-rst" policyid=382 policytype="policy" poluuid="2d99ce7c-afff-51ec-5862-0a5d00d2d330" policyname="DR-AD" service="tcp/444" trandisp="noop" duration=5 sentbyte=449 rcvdbyte=313 sentpkt=5 rcvdpkt=4 appcat="unscanned" mastersrcmac="40:06:d5:2a:4f:d7" srcmac="40:06:d5:2a:4f:d7" srcserver=0 dsthwvendor="VMware" dstosname="Windows" dstswversion="8" dstunauthuser="administrator" dstunauthusersource="kerberos" masterdstmac="00:50:56:93:a7:a2" dstmac="00:50:56:93:a7:a2" dstserver=0
And the thing I actually want is for each log, it will be one alert, not like now.