I would like to forward some of the logs (MS Event Logs) to another Log management appliance.
This problem breaks down into two parts. 1. Selectively forward syslogs --> This is easily configured in ossec.conf 2. Strip ossec specific parts of the log and forward the rest to the log management appliance which can parse native Event Logs. It is the second part that I have not been able to figure out. I suspect this would involve a perl script stripping and forwarding the logs. has anyone tried this? Thanks Ash
