Select Page

Sending Wazuh syslog output to precinct

Welcome Forums Integrations Sending Wazuh syslog output to precinct

  • This topic is empty.
Viewing 1 post (of 1 total)
  • Author
    Posts
  • #3035
    Mike RiforgiateMike Riforgiate
    Keymaster

    Configuring Wazuh

    Note: For server IP, input the IP address of the Precinct Streamer node or All-In-One appliance.

    Note: Use level configuration to select specific alert levels to be sent to Precinct.  No level config will send all alerts (recommended).

    Syslog output is configured in the ossec.conf file. All of the available options are detailed in Syslog output.

     

    <ossec_config>
      <syslog_output>
        <level>9</level>
        <server>192.168.1.241</server>
      </syslog_output>
    
      <syslog_output>
        <server>192.168.1.240</server>
      </syslog_output>
    </ossec_config>

    The above configuration will send alerts to 192.168.1.240 and, if the alert level is higher than 9, also to 192.168.1.241.

    To apply the changes, restart Wazuh:

    1. For Systemd:  # systemctl restart wazuh-manager
    1. For SysV Init:  # service wazuh-manager restart

     

Viewing 1 post (of 1 total)
  • You must be logged in to reply to this topic.