Wazuh facts about logging and alerts

  • Logs will only be displayed in Kibana when there is a decoder and a hitting rule above 0
  • Option <logall> is ossec.conf logs everything, no matter if there is a rule/decoder or not, but only to archives.log and not in Kibana