You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Using wazuh-logtest to check log lines in our Windows Server 2016/2019 DHCP server log, it seems those lines with spaces in the event are not matched correctly, but those lines without spaces are?
Note that the logs come in the format with spaces.
With spaces:
Type one log per line
13,03/15/24,11:47:19,DNS Update Request,172.0.0.0,,123ABC345AAA,,0,6,,,,,,,,,0
**Phase 1: Completed pre-decoding.
full event: '13,03/15/24,11:47:19,DNS Update Request,172.0.0.0,,123ABC345AAA,,0,6,,,,,,,,,0'
**Phase 2: Completed decoding.
name: 'ms-dhcp-ipv4'
**Phase 3: Completed filtering (rules).
id: '6300'
level: '0'
description: 'Grouping for the MS-DHCP ipv4 rules.'
groups: '['windows', 'dhcp']'
firedtimes: '1'
mail: 'False'
Hello,
Using wazuh-logtest to check log lines in our Windows Server 2016/2019 DHCP server log, it seems those lines with spaces in the event are not matched correctly, but those lines without spaces are?
Note that the logs come in the format with spaces.
With spaces:
Without spaces:
Is this a bug, or am I overlooking something?
Thanks!
The text was updated successfully, but these errors were encountered: