Wazuh-agent not forwarding Windows event logs #6089
Replies: 2 comments 1 reply
-
Are you sure the Wazuh agent is registered properly as described at https://docs.securityonion.net/en/2.3/wazuh.html#adding-agents? Have you checked the log for the agent itself for additional clues? |
Beta Was this translation helpful? Give feedback.
-
Hi Doug So after doing some debugging I think it has something to do with the ability of the wazuh-agent to forward logs from Win2008rc2 in the "eventchannel" log format. I can't figure out why that one server won't log/decode correctly. I am trying to figure out if there is a default setting in Win2008rc2 that disables eventchannel logging. What I have tried:
|
Beta Was this translation helpful? Give feedback.
-
Wazuh does not seem to be forwarding EventLogs from Windows 2008 rc2. Is this disabled by default somewhere now (I was thinking that since Wazuh, OSQuery, and WinlogBeats could do the job maybe you had to enable it)? I am pretty sure I was getting those winlogs before I updated to the Version of the wazuh-agent that is available in the "downloads" tab.
Beta Was this translation helpful? Give feedback.
All reactions