Syslog Connection status #28162
Replies: 2 comments
-
|
Hi @adilraad2001, It is not possible to detect if a syslog client is online or not, since being only a syslog client it can be totally invisible to be seen by any tool. On the other hand wazuh-analysisd, the daemon in charge of processing events and generating alerts, only reacts to stimuli (events), i.e. it will only generate alerts from events that arrive to wazuh-manager and cannot generate alerts from βevents that do not arriveβ. But there are workarounds that you could implement. For example, if your devices are ping enabled and from somewhere you have visibility of all of them, you can create a script to ping the list of devices, and when they do not respond send an event to wazuh-manager to generate an alert that the device is off or does not respond to the ping. We also have an issue related to this: #13856 Regards |
Beta Was this translation helpful? Give feedback.
-
|
I closed it because it had been inactive for more than 7 days. Please reopen it if necessary. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Hello Guys im new here
and i have a Question is there any way i can detect a syslog device is it online or offline
because i integrate a lot of device with syslog with my wazuh
but i can monitor every one is there any way i can detect if any Syslog device disconnected so connection status of it ?
Beta Was this translation helpful? Give feedback.
All reactions