Sophos Firewall logs and Wazuh: the newer syslog layout matches no decoder
Sophos Firewall can send syslog in two layouts. Wazuh 4.14.7 reads one of them. If your firewall uses...
Tag archive
Sophos Firewall can send syslog in two layouts. Wazuh 4.14.7 reads one of them. If your firewall uses...
FortiGate sends its logs to Wazuh, failed admin logins show up, and denied traffic does not. On Wazuh...
You point pfSense at Wazuh, the logs arrive, and the dashboard stays empty. Most people assume the...
If you run Wazuh 4.x with your own rules and decoders, the 5.0 release changes more than the version...
If you load a large set of custom Wazuh rules, wazuh-analysisd -t and ossec.log can tell you that...
A custom Wazuh rule that never fires rarely has a broken regex. In our lab the usual story is...
A ZoomEye fingerprint count of internet-visible Wazuh deployments, why a security platform concentrates estate knowledge and detection logic, and which of its surfaces belong on the internal network.
OSSEC vs Wazuh: File Integrity Monitoring and Active Response OSSEC and Wazuh share...
A question we got on LinkedIn: one Wazuh agent reads the logs of 1,600 firewalls, the dashboard shows...
In the last 24 hours, two people running Wazuh 4.14.7 in production hit the same defect from...
You write a child rule for a stock Wazuh rule, drop it into /var/ossec/etc/rules/, and run the config...
You enable the Wazuh ms-graph module for auditLogs/signIns. The module logs clean scans. With...