8000 No alerts for http status code 200 · wazuh wazuh · Discussion #28637 · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

No alerts for http status code 200 #28637

Closed Answered by matias-braida
meimi039 asked this question in Q&A
Discussion options

You must be logged in to vote

Hi,

I could reproduce the problem on my local machine with the information you sent me previously.

There are issues indexing these event logs. The problem is the field named "timestamp" in your custom decoder.
The format of this field is not the expected, the format used is ISO 8601 (YYYY-MM-DDTHH:MM:SSZ). In future Wazuh version 5.x the timestamp fields format will be configurable.

A workaround for this situation could be:

  • Change the field name in your custom decoder for example "timestamp1"
  • Change the current "timestamp" field format to match ISO 8601.

Replies: 4 comments 6 replies

Comment options

You must be logged in to vote
1 reply
@meimi039
Comment options

Comment options

You must be logged in to vote
4 replies
@meimi039
Comment options

@matias-braida
Comment options

@meimi039
Comment options

@matias-braida
Comment options

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@meimi039
Comment options

Answer selected by Damian-Mangold
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants
0