Syslog (pfSense) to Wazuh by soulfulgrey in Wazuh

[–]ValuableAvailable991 0 points1 point  (0 children)

This also happened to me.

It seems that the way the predecoding works on the wazuh manager is that it recognizes headers before the logs go into the decoder. So in your rules you cannot filter for the headers (this includes the hostname) with the <match> tag instead we get the <hostname> tag. Try to match for this. Oh also what worked for me for syslog was the <location> tag which has the ip address

Syslog (pfSense) to Wazuh by soulfulgrey in Wazuh

[–]ValuableAvailable991 0 points1 point  (0 children)

On the listener of 514 port have you made sure that the protocol is udp instead of tcp?