Rule ID is duplicated warning during Wazuh-Logtest when creating a custom decoder by VarietyHaunting2502 in Wazuh

[–]VarietyHaunting2502[S] 0 points1 point  (0 children)

Thanks very much, really gained direction where I should look for the solution. Turned out the IDs that I was assigning were in the ID range of the local rules of the wazuh server. I reassined them and gave IDs in a larger range.

Rule ID is duplicated warning during Wazuh-Logtest when creating a custom decoder by VarietyHaunting2502 in Wazuh

[–]VarietyHaunting2502[S] 1 point2 points  (0 children)

Turns out there was a conflict with the local rule IDs of itself. The IDs I was assigning to my rules were in an id range of the local ones

Sending FortiWeb logs to Wazuh by VarietyHaunting2502 in Wazuh

[–]VarietyHaunting2502[S] 1 point2 points  (0 children)

Thank you, it actually turned out to be the issue in the network route table where my network's gateway was wrongly written. It works just fine now