You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi, I’m pretty newbie using wazuh, and I’m trying to configure it to avoid collecting certain user-generated events, represented by an external service that works in the background, and that daily performs many requests on the various corporate endpoints. Wazuh sees these and saves them as logs, so I followed this #459guide where you were going to ignore the generated events, and the dashboard actually doesn’t show them anymore. The problem is that I activated the notification by email, and daily the emails arrive saying that the queue of wazuh, installed in a certain agent is full. I did a check and on the dashboard these requests are not shown but from the time of the email notification I realized that it is this service. I would like to know if there is a way to actually ignore these logs directly from the agent or the only solution is to set the anti-flooding mechanism.
The rule I’m using is this
Hi, I’m pretty newbie using wazuh, and I’m trying to configure it to avoid collecting certain user-generated events, represented by an external service that works in the background, and that daily performs many requests on the various corporate endpoints. Wazuh sees these and saves them as logs, so I followed this #459 guide where you were going to ignore the generated events, and the dashboard actually doesn’t show them anymore. The problem is that I activated the notification by email, and daily the emails arrive saying that the queue of wazuh, installed in a certain agent is full. I did a check and on the dashboard these requests are not shown but from the time of the email notification I realized that it is this service. I would like to know if there is a way to actually ignore these logs directly from the agent or the only solution is to set the anti-flooding mechanism.
The rule I’m using is this
Thank you in advance for your help.
The text was updated successfully, but these errors were encountered: