Hello Team,
I hope you are doing well.
One of our clients has a requirement to monitor AWS ElastiCache logs using Wazuh. Could you please confirm if this is possible? If so, we would appreciate your guidance on how to configure and integrate these logs with Wazuh.
Looking forward to your support.
Regards
Chandra
Hi Chandra,
You can forward the Elasticache Logs to Cloudwatch.
Ref: ElastiCache logging destinations
AWS CloudWatch Logs is a service that allows the users to centralize the logs from all their systems, applications, and AWS services in a single place.
And you can monitor Amazon CloudWatch Logs in Wazuh.
Monitoring AWS-based services - CloudWatch Logs
Let me know if you need any further information on this.
You can use these documents to create rules:
Custom rules
You can use the ruleset test tool to test the logs if they match your custom and rules.
Testing decoders and rules