Installing the Wazuh agent ensures that events are properly sent to the Wazuh XDR server.
logall,logall_json are turned to yes<ossec_config> <global> <jsonout_output>yes</jsonout_output> <alerts_log>yes</alerts_log> <logall>yes</logall> <logall_json>yes</logall_json>…
root@wazuh:~# service wazuh-manager restartroot@wazuh:~# service wazuh-indexer restart
You will find events in the Threat Hunting section of your remote IDS Artica server with the rule.groups:suricata
