Logs in Archives But No alerts

4 views
Skip to first unread message

Milene Hadil BEDOUHENE

unread,
8:23 AM (12 hours ago) 8:23 AM
to Wazuh | Mailing List

Dear Wazuh Support Team,

I hope you are doing well.

I am writing to report an issue with my Wazuh server. I have configured it properly and also integrated both Zeek and Suricata into my environment. I created several rules using Zeek, and they are working perfectly.

However, I am currently trying to use Sysmon to generate alerts when a port scan is performed. I can see the logs in archives.json, but no alerts are being generated in alerts.json.

In the dashboard, I am receiving alerts generated by the default Wazuh rules, but none of my custom alerts appear. I am also using Filebeat in my setup.

Thank you for your support.

Best regards,

Reply all
Reply to author
Forward
0 new messages