Sending Wazuh syslog output to precinct

    Configuring Wazuh

    Note: For server IP, input the IP address of the Precinct Streamer node or All-In-One appliance.

    Note: Use level configuration to select specific alert levels to be sent to Precinct.  No level config will send all alerts (recommended).

    Syslog output is configured in the ossec.conf file. All of the available options are detailed in Syslog output.



    The above configuration will send alerts to and, if the alert level is higher than 9, also to

    To apply the changes, restart Wazuh:

    1. For Systemd:  # systemctl restart wazuh-manager
    1. For SysV Init:  # service wazuh-manager restart


